Everything an admin is responsible for: who is in the workspace, what they can reach, how they sign in, and what happens to the data when they leave.
A member is anyone who can open or edit content in the workspace, and a member takes a seat. Someone holding a read-only share link is not a member and is not billed — that is the distinction that decides most invoices.
Permissions are scoped rather than global: a role applies within a workspace and can be narrowed per project. The model is least privilege — access is granted, not inherited by default.
Granular team roles are part of the Studio plan and above.
A guest can be given access to specific projects without seeing the rest of the workspace. For a client or an external freelancer this is usually the right level — narrower than a member, more than a link.
Enterprise workspaces can authenticate through your existing identity provider, so access follows the same joiner and leaver process as everything else in the company.
With directory sync, accounts are created and — the part that actually matters — deactivated automatically from your directory. It closes the gap where someone leaves the company and keeps a workspace login for three months because nobody told anyone.
Availability
SSO and SCIM are part of the Enterprise plan. Setting them up involves us — start at sales.
An admin can enforce a local-only storage policy across the whole workspace, which disables cloud sync for everybody rather than relying on individual settings. Real-time collaboration and share links are unavailable while it is in force, because both need the server. See Storage, sync & encryption.
AI-assisted features are opt-in and can be disabled for the workspace. When they are used, only the context selected for that request goes to the model provider listed in the subprocessor list. Workspace content is not used to train models.
Security-relevant events are recorded append-only and retained according to the retention policy. This is what an incident review reads afterwards.
Deletion is a request that is verified before it is carried out — otherwise it would be a way to destroy someone else's data.
Because Ceyu is local-first, deleting a workspace does not touch the copies on your own disks. Those are yours to keep or remove.