Administration

Workspace settings

The settings that apply to everyone in the workspace.

Where this lives. Sign in and open /settings in the app.

What it does

Settings is the workspace's control panel, organized as a tab strip: General, My account, Security, Members, Roles, Branding, Compliance, Providers, Feature Flags, and Audit Logs. Most tabs are workspace-wide and change depending on your role; My account and part of Security are about you personally, not the whole workspace.

Before you start

  • Changing roles, inviting, or removing members needs the manage_users permission.
  • Billing and workspace API keys are gated by manage_billing, and every change to them is audited.
  • Turning on two-factor needs an authenticator app on your phone or a password manager that supports TOTP codes.
  • A few cards only platform staff can see appear on the General tab. They are covered briefly below since most readers will never see them.

Set it up, step by step

  1. Open Settings. The General tab shows your workspace's name, its slug, and your role in it. This display is read-only in the app; no rename control appears on this tab. [VERIFY: whether a workspace can be renamed anywhere else in the app]
  2. Further down General, an Operating posture card summarizes compliance settings as pills, for example how many approval gates are active and whether the unsubscribe footer is required, linking through to the Compliance tab for full detail. A Billing & API keys card links out to the Billing and Providers/Integrations tabs.
  3. Go to Members to see everyone in the workspace with their role. If you can manage users, each person has a role dropdown and, except for yourself, a Remove link (you can only remove an owner if you are one yourself).
  4. Still on Members, use Invite a teammate: enter an Email, pick a Role (any role except owner), and click Send invite. Invites are emailed and expire after 7 days; the accept link also appears on screen so you can send it yourself. Pending invites show a Revoke link.
  5. Open Roles to see the server-enforced permission matrix for every role, including any custom roles your workspace has created. Sensitive actions still require approval regardless of which role performs them.
  6. For notification email preferences, go to My account (personal, not workspace-wide) and find Email from us. Security, billing, and support emails always arrive; two are optional: Offers and product news ("Occasional announcements and promotions. Never more than a few a month.") and Workspace alerts ("An email when something needs you before you next sign in — a held campaign, a sender to reconnect. The bell in the app always has the full trail.").
  7. Also on My account: change your Name, your Password (signs out every other session), or your sign-in email (a confirmation link goes to the new address first, so nothing changes until you open it). Your data lets you export everything or delete your account by typing DELETE and your password.
  8. Go to Security for two-factor on your account. Click Turn on two-factor, scan the QR code (or type the setup key shown underneath) with an authenticator app, enter the six-digit code, and click Confirm and turn on. Recovery codes are shown exactly once; click Copy all, store them, then I saved them. Once enabled, use Regenerate recovery codes or Turn off two-factor, both needing a current or recovery code.
  9. If your workspace manages TOTP codes for shared mailbox accounts, the Authenticator card further down Security lets you click Manage entries to add or rename them, so a team running many mailboxes does not need forty separate phone entries.
  10. Branding, Compliance, Providers, Feature Flags, and Audit Logs round out the remaining tabs: white-label identity, suppression and approval policy, connected adapters, workspace-level flag overrides, and an append-only log of who did what.

What you should see

An invited teammate appears in the pending invites list immediately with a pending · [role] tag. Turning on two-factor moves the status pill on the Security tab from Off to On · [N] recovery codes left. Saving your name or password shows a confirmation toast; changing your email specifically warns that nothing changes until the confirmation link is opened.

Common problems

  • No way to rename the workspace: the General tab only displays the name and slug; this documentation could not confirm a rename path in the reviewed code.
  • Can't see the Staff console or Platform administration cards: these appear only for platform staff and platform admins respectively. If you are a regular workspace member or admin, you will not see them, and that is expected.
  • Can't change a member's role or invite anyone: you need the manage_users permission. Ask an owner or admin to grant it or make the change for you.
  • Lost your two-factor device: use one of your saved recovery codes in place of a six-digit code; each works once.
  • Turning off two-factor is blocked: it requires a current code from your app or an unused recovery code. Without either, you cannot disable it from this screen.

Common questions

Should everyone have the same role?

No. Give each person the narrowest role that lets them do their job. The question to ask of any role is not what it allows but what it would cost if that account were taken over.

Who should turn on two-factor?

Everyone who can send mail or spend money, which in most workspaces is everyone. An outbound account is a credible target precisely because it can reach thousands of people in your name.

Last updated September 19, 2026. Written by the team that operates the platform.

Workspace Settings: Members, Notifications and Security