Workspace, tenants & RBAC

How workspaces, brand tenants, and role-based access fit together in the control plane.

Creytix platform studio — five module chips and Connect tool lanes

Overview

A workspace is the container for one site — its Brand DNA, its content, and the Connect tools attached to it. If you run more than one brand, each one gets its own workspace rather than sharing a single free-for-all account. Access to a workspace, and to what a given teammate can do inside it, is controlled at the workspace level.

How it works

Every module and every Connect tool operates against whichever workspace is currently open — never a global instance shared across brands. That isolation is the foundation: a teammate working in one workspace doesn't see another brand's content, Brand DNA, or Connect connections unless they're also a member of that workspace.

Team access is granted per workspace. Within a workspace, responsibilities split roughly along who can review and approve work versus who can push a release — the same review-then-release pattern that runs through Creytix Inspector and Creytix Ship.

Steps

  1. •

    Open or switch workspace

    Confirm which workspace you're in before you start — see Connect your workspace.

  2. •

    Confirm the module scope

    Everything you see in the module switcher and in Connect is scoped to that workspace alone.

  3. •

    Invite teammates

    Add teammates to the workspace they need — each brand's workspace is where its own team is granted access.

  4. •

    Know who can ship

    Before a release goes out through Creytix Ship, confirm who on your team has approval responsibility versus who can push to production.

Capabilities

  • Workspace isolation — one workspace per site or brand; content, Brand DNA, and Connect connections don't leak across workspaces.
  • Workspace-scoped module switcher — the eight departments always reflect the workspace you have open, not a global view.
  • Team membership per workspace — teammates are added to the specific workspace they work in.
  • Review-then-release pattern — the same approval-before-production shape used by Inspector and Ship applies to who can act inside a workspace.

Limits & honest scope

This is the area of the platform we'd rather under-promise on than over-describe.

  • Fine-grained, per-feature role definitions (who can edit content but not send a campaign, for example) are still being built out. Today's model leans on workspace-level isolation more than deep in-workspace permission granularity.
  • Self-serve workspace invites and a full audit trail of who-did-what are not yet documented as customer-facing flows — workspace and team setup currently runs through your Creytix team.
  • If your organization has specific access-control requirements, raise them directly with your Creytix contact rather than assuming a specific role model exists today. Check the changelog as this area matures.

Have a code from email or QR?