title: "Manage workspace access and linked workspaces" header_image: "" authors:

  • "Tealfabric Team" published_at: "2026-09-14" category: "general" summary: "How tenant administrators grant access to existing users, review join requests, and create linked production workspaces." draft: false

Who this is for

Tenant administrators (tenant_admin) who manage User Management and Organization settings in the tenant console.

Roles apply per workspace

Your role in the workspace selected in the top-left switcher controls what you can do there. Being a tenant admin on workspace A does not automatically give you admin rights on workspace B unless you have been granted tenant_admin (or equivalent) on B.

See also: Workspace user roles.

Grant access to someone who already has an account

  1. Open User Management.
  2. Choose Grant access.
  3. Enter the person’s email and the role they should have in this workspace (User, Viewer, Webapp user, or Tenant admin).
  4. They receive an email and must accept the invitation before the grant is active.

You cannot create a second login with the same email. Use Grant access instead of Add user when the person already uses Tealfabric.

Add a new person

Use Add user when no account exists for that email. They receive a welcome message with a temporary password.

Pending access requests

When someone tries to register using an organization name that already exists, they can request access. Pending requests appear at the top of User Management. Approve sends an invitation flow (or grants access for new provisioning rules); Deny closes the request.

Linked workspaces (Organization settings → Workspaces)

Your organization can own multiple production workspaces in one workspace group:

  • Each workspace has its own data, integrations, billing, and security settings.
  • Only an administrator of the owner workspace can create another linked workspace.
  • The owner workspace must be on Basic, Premium, or Enterprise, or be a system subscription. Free and Starter cannot create linked workspaces.
  • The owner plan may also limit how many linked workspaces you can create (max_linked_workspaces).

From Workspaces you can also create a sandbox for the current production workspace (non-production copy for testing).

What stays separate

Linked workspaces do not share SSO configuration, API keys, ProcessFlow keystores, or agent guardrails. Connect integrations and SSO separately in each workspace.

Related documentation