Set up your workspace
What you do as the admin of a Ceven workspace. Add your team, connect the apps everyone works from, and decide who can reach what.
Your workspace is where your team and your agents work together. Everything you connect, build or share lives inside it, and everyone you invite starts from the same tools and the same shared knowledge.
If you created the workspace, you are its admin. Everyone you invite joins as a member. Those are the only two kinds of people in a workspace, so there is no permissions matrix to learn. You look after the workspace, and your team gets on with the work inside it.
Add your team
Open Settings, then Workspace Team, or use Invite people in the workspace header. Both open the same dialog.
- Type the email addresses you want to add. You can paste several at once, separated by commas, and send them together.
- Each person gets an invitation and joins as a member when they accept it.
- If you would rather not send email at all, copy the join link from the same dialog and share it however you like.
An invitation that nobody has accepted yet can be cancelled, and cancelling it leaves nothing behind. Access begins when somebody accepts, never before.
Invite the address they will actually sign in with.
An invitation is tied to the email address you typed. If someone signs in with a different address they arrive as a new person with an empty workspace, rather than joining yours.
Connect your apps once, for everyone
You connect Slack, Google, GitHub, Notion, your database and anything else on behalf of the whole workspace. Your team then works with those connections without being asked to link a personal account and without ever seeing the credentials behind them.
Two things follow from that, and both are deliberate:
- Nobody on your team adds a connection of their own. When they need a new tool, they ask you, and you decide.
- When you disconnect an app it stops being available to everyone at the same moment. There is no personal copy still running somewhere.
Decide what your team can reach
The knowledge your team works from lives in libraries: documents, records, exports, notes, whatever the work needs. Every workspace starts with one that everybody can use, and you add more as you go.
For each library you create, you choose who it is for. Some are open to the whole workspace. Others you keep to the people you name, and only those people can open them or build on them.
A library is the control, not a second list.
Limiting a library also limits the agents that read it. An agent built on a library that only three people can open simply is not available to anyone else, automatically, with nothing extra for you to maintain.
Share what your team builds
Whoever creates an agent, a room, a chat or a file owns it and can share it. When they share, they choose how far it goes: someone can be allowed to look at it, to run it without changing it, or to change it and pass it on themselves.
Sharing hands over the one thing that was shared. It does not change where anyone stands in the workspace, it does not touch anything else the owner has, and it can be taken back at any time.
Agents stay inside the limits you set
An agent never reaches further than the person running it. If a teammate cannot open something on their own, an agent they run cannot open it for them either, no matter who built that agent.
That is what makes an agent safe to hand around. You can give the whole team an agent that works with sensitive material, and each person still sees only the part they were already allowed to see.
What being the admin does and does not mean
You look after people and the tools they share, not everything they write.
You can invite people and remove them, connect and disconnect apps, create libraries and decide who is in them, take back anything that has been shared, and open any agent in the workspace to see how it was built.
You cannot read your team's private conversations, or run somebody else's agent as though it were your own. Reviewing an agent shows you how it works. It does not hand you the reach of the person who made it.
When somebody leaves
Remove them from the workspace and their access ends there. The work they shared with the team stays where it is, so nothing your colleagues depend on disappears with them, and their private conversations are not passed on to anyone.