Manage workspace settings, access, credentials, billing, and offboarding as a workspace Owner or Admin.
Workspace settings affect the whole organization. A Team Admin can edit their team’s details but does not receive workspace administration access. Billing requires billing-management access; Portal appears only when enabled.
Manage access
Choose the least-privilege role
Zentrik workspace roles are:
- Owner: workspace ownership and the most sensitive workspace-level controls
- Admin: workspace settings, integrations, API keys, team administration, and product configuration
- Editor: day-to-day creation and editing in product workflows without access to workspace Settings
- Viewer: read-only workspace participation
Keep at least one active Owner. Do not use Owner as the default collaboration role. Review Admin access whenever responsibilities change.
Manage members and invitations
Open Settings → People to review members and pending invitations. Use Members to change workspace roles and Teams for team membership. Check delivery state before resending an invitation. Follow Invite people and manage access for the full procedure.
Find the right setting
Use the Settings map
The Settings hub groups product configuration and workspace administration:
- Discovery: evaluation, workflow, and property configuration
- Definition: requirements, documentation templates, and user-story standards
- Delivery: cycles and team capacity
- Integrations: connected evidence and delivery providers
- API Keys: credentials for MCP clients and the external API
- People → Members: workspace members, workspace roles, and invitations
- People → Teams: operational teams, team membership, and team roles
- Billing: plan, usage, and invoices when the role can manage billing
- Portal: Ideas Portal access and configuration when enabled
- Workspaces: workspace naming, switching, and defaults; only Owners can add another workspace
The options shown in Settings depend on the workspace plan and enabled capabilities.
The top-left menu shows the current team. Use Switch workspace in that menu before administering another workspace. Members and Teams always apply to the selected workspace.
Review billing and workspace boundaries
Open Settings → Billing for the plan, usage, limits, and invoices when your role permits it. See Pricing for current packaging.
In Settings → Workspaces, Owners and Admins can rename workspaces they administer, set a default, and declare company email domains. Include each domain your own team uses so imported conversations can distinguish coworkers from customers. Only Owners can create an additional workspace.
Use Switch workspace in the top-left menu before administering another workspace. Keep separate workspaces when teams or clients need separate access and context.
Protect access and credentials
Protect integrations and API keys
Treat provider credentials and Zentrik API keys as secrets:
- create separate credentials for distinct systems or agents when practical
- name keys by purpose and owner
- grant only the scopes the workflow needs
- store secrets in an approved secret manager or environment variable
- never paste a key into documentation, chat, source control, screenshots, or support messages
- revoke credentials that are unused, exposed, or owned by a departing teammate
- confirm the active Zentrik workspace before connecting an MCP client
Use MCP setup or the REST API reference for the relevant authentication flow.
Offboard safely
Before removing a teammate:
- Transfer ownership of important product decisions, documents, integrations, and operating routines.
- Identify credentials, connected providers, or external automations they own.
- Create replacement credentials where needed.
- Revoke the person’s invitations or remove their membership.
- Revoke or rotate affected API keys and provider credentials.
- Verify that required integrations and scheduled imports still run.
Removing a member is not a substitute for rotating a credential they could access.
Review and get help
Quarterly review checklist
Periodically review active Owners, Admin responsibilities, pending invitations, credential owners, billing access, and workspace boundaries. Revoke unused credentials and reconcile expired invitations.
Support and trust
Use Security and trust for current public assurance information. For a workspace-specific access, billing, or configuration issue, use the Still stuck? path below and include the workspace name, the screen, what you expected, and what happened.
Do not include passwords, API keys, access tokens, private customer content, or full diagnostic exports in the initial support message.
Troubleshooting
A teammate cannot open Settings
Workspace settings are restricted to Owners and Admins. Confirm the person’s workspace and role; a Team Admin can edit that team’s details but cannot manage workspace users or workspace-wide settings.
An invitation email failed or expired
Check the Invitations view, confirm the email, and resend or revoke from the recorded invitation state. Avoid creating repeated invitations without reconciling the existing one.
A billing, portal, or workspace control is missing
Visibility depends on role and workspace capabilities. Owners and Admins can manage existing workspaces, but only Owners can create another one. Billing requires billing-management access, and Portal appears only when enabled.
Continue from here
Related guides
Did this guide answer your question?
Your response helps us prioritize missing or unclear documentation.
Still stuck?
Send your question to Zentrik support. This guide will be included automatically.