0.23.0

Beta

Build your own roles, and give people access to specific workspaces.

Roles you define, instead of three we picked

Settings → Roles is new. You can create a role by duplicating one of the built-in ones and adjusting it, or by starting from nothing and ticking only what you want. A permission matrix shows every role against every capability, so you can read the whole picture at once instead of opening each role to find out what it does.

A typical use: copy Admin, remove billing and the ability to invite people, call it Ops, and give it to whoever runs the day to day. Or start blank, tick only the profile permissions, and hand that to a contractor.

Roles are available on Pro and above. If you move to a lower plan, the roles you already built keep working exactly as they are and everyone keeps the access they had. Only the editor is switched off, so nothing silently changes for anyone on a role you narrowed.

A role is per person, not per workspace

Someone holds one role across your whole account. What changes per workspace is which workspaces they can reach, not what they can do inside them. If you need someone to be an admin in one place and a member in another, that is two people or two accounts.

Members are now listed by person

Settings → Members groups by person rather than by grant, so someone who reaches three workspaces is one row with three workspaces on it, not three rows. Their role is set once, in one place, and applies everywhere they go.

You can change which workspaces someone reaches from the same row.

Removing a workspace from someone removes what they connected there

This one is worth reading before you need it. When you take a workspace away from someone, the vendor accounts THEY connected in that workspace are disconnected and their stored credentials are deleted. Any profile exposing those connections stops serving their tools.

Accounts connected by other people in the same workspace are untouched, and so is everything that person connected in workspaces they keep. The confirmation dialog tells you how many workspaces are affected before you commit.

Invites now ask which workspaces

When you invite someone you now choose the workspaces they can reach, and the invite will not send until you do. Previously an invite with nothing selected granted the whole account, which meant the widest access was the one you got by not deciding. Selecting every workspace is still available and still grants the whole account, including workspaces you add later, but it is now a choice you make rather than a default you inherit.