Help / Members & access policies
Members & access policies
Updated July 25, 2026
There are two ways to give someone access, for two different needs. Workspace membership decides who is on the team and their broad role. An access policy grants one person specific permissions on one resource — narrower, and often time-limited.
Add a workspace member
- Open Manage → Members and choose "Add member".
- Search the directory by name or email and pick the person.
- Choose a role — owner, admin, member or viewer — and add them.
From the members table you can change a role or remove someone. Organisation-wide membership works the same way under Organisation settings → Members.
Grant access to a single resource
Under Manage → Access policies, choose "Grant access":
- Pick the user by searching their name or email.
- Choose the resource type, then pick the exact resource — for a secret you drill in project → environment → secret; a workspace grant applies to everything.
- Add the permissions to grant (for example secrets:read), and optionally a duration in hours (0 means permanent).
Granted policies show in a list; revoke any one the moment it is no longer needed.
When someone asks for access
On paid plans a member can raise an access request instead of an admin granting it up front. The request and its decision both land in the audit log; approvers act under Manage → Access requests → Approvals.