Skip to main content
A workspace is the top-level Context Vault boundary. Members can only ingest, search, browse, correct, or review knowledge for workspaces they belong to.

Roles

RoleCan searchCan ingestCan correctCan inviteCan manage members
ownerYesYesYesYesYes
adminYesYesYesYesYes, except owners/admins
memberYesYesYesNoNo
viewerYesNoNoNoNo
Workspace creators become owner. Invitations can assign admin, member, or viewer; owner is not an invitable role. Invitations are emailed to the teammate and do not create membership until that user accepts the invite from the same email address.

Billing owner

Each workspace has one billing owner. By default, the billing owner is the user who created the workspace. The billing owner’s plan controls the workspace’s Context Vault document allowance. Invited admins and members can upload documents when their role allows it, but those documents count against the workspace billing owner’s allowance, not the uploader’s personal plan. For example, if a workspace is owned by an Ultimate user, a Free-plan member can upload documents into that workspace until the owner’s Context Vault document limit is reached. If an invited admin upgrades their own plan, that does not automatically transfer billing ownership for an existing workspace.

Workspace isolation

Every Context Vault document, chunk, memory, citation, feedback item, and correction is checked against workspaceId. A query for one workspace never returns another workspace’s knowledge. Use separate workspaces when the data belongs to different companies, customers, tenants, or legal entities.