# People and permissions

> Workspaces, inviting people, roles and groups.

# People and permissions

## Organisations and workspaces

An **organisation** is your company. A **workspace** is a working area inside it with its own
projects, brand settings and default voice.

Most teams need one workspace. Add more when groups genuinely shouldn't see each other's work —
separate brands, separate clients, or a sandbox that shouldn't sit next to published work.

You can belong to several and switch between them.

## Inviting people

Invite by email. An invitation can be resent or revoked before it's accepted.

## Roles

Roles determine what someone can do — view, create and edit, or administer. Assign the narrowest
role that lets someone do their job; it's easier to widen later than to explain why a share went
public.

## Groups

Groups collect people so permissions can be assigned once rather than per person. Worth setting up
before the team is large, not after.

## Workspace defaults

A workspace can set the defaults new projects inherit — default voice, brand settings, guardrails.
This is the difference between a consistent library and fifty differently-branded videos.

## Provider keys

Workspaces on the relevant plans can supply their own provider credentials, so narration and avatar
generation run against your accounts and billing rather than ours.
