Workspaces · Enterprise

Every team in its workspace. Every person with the right permission.

Bring apps and databases into a shared space, invite the team by e-mail or link and decide, permission by permission, what each role can do. The owner stays in control; whoever lacks a permission asks for approval instead of hitting an error.

vertracloud.app/dashboard/workspaces
Checkout5 members
  • Marina CostaOwner
  • Rafael LimaAdmin
  • Júlia NogueiraDeveloper
  • Caio FerreiraOperator
  • Beatriz AlvesViewer
  • Pending inviteexpires in 7 days
18atomic permissions
5–24members per workspace
≤ 12roles per workspace
Permissions

Granular permissions, not fixed roles.

A role is a combination of 19 atomic permissions across 6 groups. Read, manage, start and stop, delete: each one is a separate switch, and the server checks it on every route, not just the interface.

Applications

6

View, configure, start and stop, environment variables, files and deletion, each one separate.

  • apps:read
  • apps:manage
  • apps:lifecycle
  • apps:envs
  • apps:files
  • apps:delete

Databases

6

Details and metrics, configuration, lifecycle, credentials, the Data tab and deletion.

  • databases:read
  • databases:manage
  • databases:lifecycle
  • databases:credentials
  • databases:data
  • databases:delete

Snapshots

2

Viewing is one permission; creating and restoring is another. Not even Admin starts with the second.

  • snapshots:read
  • snapshots:manage

Members

2

See who is in the workspace, or invite, remove and change a member's role and expiry.

  • members:read
  • members:manage

Roles

1

Create, edit and delete custom roles within your tier's cap.

  • roles:manage

Activities

1

View and export the workspace activity log.

  • activities:read

Owner only

Four actions bypass every role.

  • Link and unlink a project to the workspace
  • Rename and delete the workspace
  • Turn the GitHub deploy webhook on and off
  • Turn an app's web publishing on and off
Roles

Four ready-made roles. All editable.

Every workspace starts with Admin, Developer, Operator and Viewer. Rename, adjust or delete any of them and create your own within the tier's cap. The four count toward that cap like any other role.

  1. Admin

    Everything except creating and restoring snapshots. Restoring is too destructive to inherit; the owner enables it separately.

    17 of 18 permissions
  2. Developer

    Configures, deploys and works on files, variables and data of apps and databases, but deletes neither.

    13 of 18 permissions
  3. Operator

    Sees the state and runs the lifecycle: start, stop and restart. Changes no configuration or data.

    7 of 18 permissions
  4. Viewer

    Read-only: apps, databases, snapshots, members and activity. No writes.

    5 of 18 permissions
A member never grants a permission they don't have, to themselves or to anyone else. The attempt returns an error, not silence.
Invites

Joining is by e-mail or link. Leaving is when you decide.

Whoever has the members permission invites; the invitee sees a preview of the workspace and accepts or declines.

E-mail invite

Tied to one address, expires in 7 days and is only accepted by the account with that e-mail.

Link invite

Multi-use, expires in 24 hours, with an optional usage cap and revocable at any time.

Time-boxed access

Invite a freelancer for 30 days: the expiry travels with the invite and applies to whoever joins through it.

Decline by default

Any account can turn off e-mail invites in its settings. A pending invite counts toward the member limit.

Day to day

What the team shares beyond the projects.

A workspace is not just a member list. Everything the operation needs to work as a group lives inside it.

Vertra Flow

The workspace's apps and databases show up as live nodes on each member's canvas, with groups and attachments.

Activity log

Who did what, on which resource and when. Exportable by anyone with the activities permission.

Action requests

No permission to delete, create or restore? The button becomes a request. Whoever can approve decides within 24 hours.

Limits

The plan tier sets the team size.

Workspaces are available on the Enterprise plan. The chosen tier, from 4 GB to 32 GB, sets how many members and how many roles fit in each workspace.

5 to 24 members per workspace, depending on the tier

TierMembersRole cap
Enterprise-4 · 6 · 85–104
Enterprise-12 · 14 · 1613–156
Enterprise-18 · 20 · 22 · 2416–198
Enterprise-26 · 28 · 3020–2210
Enterprise-322412

The four seed roles count toward the cap.

What if the plan expires?

Nobody is removed and nothing is deleted. Reading continues; invites, edits and actions are frozen until the plan is back. Even a deleted workspace keeps its name in the billing history.

Questions

Frequently asked questions

The essentials before opening the team's first workspace.

Which plans include workspaces?

Enterprise only. Each tier of the range, from 4 GB to 32 GB, brings a member cap per workspace (5 to 24) and a role cap (4 to 12). An invited member doesn't need a plan: the owner pays.

Do I need a plan to be invited?

No. Any Vertra Cloud account can accept an invite. The workspace owner's plan is what unlocks the workspace features.

What is the difference between a role and a permission?

A permission is the atomic action, like starting an app or viewing a database's credentials. A role is the set of permissions you assign to a member. The four ready-made roles are a starting point; you edit them or create your own.

Can a member delete a project from my workspace?

Only if their role has the delete permission. Without it, the button becomes an action request, and whoever has both the members permission and the delete permission approves or rejects it. The request expires after 24 hours without a decision.

What happens to the workspace if I leave Enterprise?

The workspace freezes: reading continues for everyone, but invites, edits and actions return a plan error until you're back. No member is removed and no data is deleted.

Available on Enterprise

Start with 4 GB and bring the team.

Pick the tier, create the workspace and send the first invite the same day.