Applications
6View, configure, start and stop, environment variables, files and deletion, each one separate.
- apps:read
- apps:manage
- apps:lifecycle
- apps:envs
- apps:files
- apps:delete
Workspaces · Enterprise
Bring apps and databases into a shared space, invite the team by e-mail or link and decide, permission by permission, what each role can do. The owner stays in control; whoever lacks a permission asks for approval instead of hitting an error.
A role is a combination of 19 atomic permissions across 6 groups. Read, manage, start and stop, delete: each one is a separate switch, and the server checks it on every route, not just the interface.
View, configure, start and stop, environment variables, files and deletion, each one separate.
Details and metrics, configuration, lifecycle, credentials, the Data tab and deletion.
Viewing is one permission; creating and restoring is another. Not even Admin starts with the second.
See who is in the workspace, or invite, remove and change a member's role and expiry.
Create, edit and delete custom roles within your tier's cap.
View and export the workspace activity log.
Owner only
Every workspace starts with Admin, Developer, Operator and Viewer. Rename, adjust or delete any of them and create your own within the tier's cap. The four count toward that cap like any other role.
Everything except creating and restoring snapshots. Restoring is too destructive to inherit; the owner enables it separately.
17 of 18 permissionsConfigures, deploys and works on files, variables and data of apps and databases, but deletes neither.
13 of 18 permissionsSees the state and runs the lifecycle: start, stop and restart. Changes no configuration or data.
7 of 18 permissionsRead-only: apps, databases, snapshots, members and activity. No writes.
5 of 18 permissionsWhoever has the members permission invites; the invitee sees a preview of the workspace and accepts or declines.
Tied to one address, expires in 7 days and is only accepted by the account with that e-mail.
Multi-use, expires in 24 hours, with an optional usage cap and revocable at any time.
Invite a freelancer for 30 days: the expiry travels with the invite and applies to whoever joins through it.
Any account can turn off e-mail invites in its settings. A pending invite counts toward the member limit.
A workspace is not just a member list. Everything the operation needs to work as a group lives inside it.
The workspace's apps and databases show up as live nodes on each member's canvas, with groups and attachments.
Who did what, on which resource and when. Exportable by anyone with the activities permission.
No permission to delete, create or restore? The button becomes a request. Whoever can approve decides within 24 hours.
Workspaces are available on the Enterprise plan. The chosen tier, from 4 GB to 32 GB, sets how many members and how many roles fit in each workspace.
5 to 24 members per workspace, depending on the tier
| Tier | Members | Role cap |
|---|---|---|
| Enterprise-4 · 6 · 8 | 5–10 | 4 |
| Enterprise-12 · 14 · 16 | 13–15 | 6 |
| Enterprise-18 · 20 · 22 · 24 | 16–19 | 8 |
| Enterprise-26 · 28 · 30 | 20–22 | 10 |
| Enterprise-32 | 24 | 12 |
The four seed roles count toward the cap.
Nobody is removed and nothing is deleted. Reading continues; invites, edits and actions are frozen until the plan is back. Even a deleted workspace keeps its name in the billing history.
The essentials before opening the team's first workspace.
Enterprise only. Each tier of the range, from 4 GB to 32 GB, brings a member cap per workspace (5 to 24) and a role cap (4 to 12). An invited member doesn't need a plan: the owner pays.
No. Any Vertra Cloud account can accept an invite. The workspace owner's plan is what unlocks the workspace features.
A permission is the atomic action, like starting an app or viewing a database's credentials. A role is the set of permissions you assign to a member. The four ready-made roles are a starting point; you edit them or create your own.
Only if their role has the delete permission. Without it, the button becomes an action request, and whoever has both the members permission and the delete permission approves or rejects it. The request expires after 24 hours without a decision.
The workspace freezes: reading continues for everyone, but invites, edits and actions return a plan error until you're back. No member is removed and no data is deleted.
Available on Enterprise
Pick the tier, create the workspace and send the first invite the same day.