Sign in →
1 min read

Workspace Admin — Overview

Operator account management — invite teammates, manage roles, mint API keys, configure SSO, view the audit log. The first place you visit on a new workspace.

Updated 2026-07-29Suggest edits

Workspace Admin is the operator-account control room. Invite your team, set their roles, mint API keys for your services, configure SSO, manage feature flag visibility, and audit who did what. It opens from the profile popover in the top-right header — not a top-level nav item, because it's configuration, not day-to-day work.

What Workspace Admin is for#

Operator identity, operator access, and operator self-service. It does NOT manage your customers (Customer Success → Customers does that), and it does NOT manage your subscriptions (Pricing Studio → Subscriptions). Workspace Admin is purely for the humans who run your Aforo workspace.

Pages in this section#

The twelve Workspace Admin tabs#

Inside the console the Workspace Admin is a single page with twelve tabs. Each tab owns one slice of operator administration:

TabWhat it does
MembersInvite teammates, change their role (Owner / Admin / Member / Developer / Billing Admin / …), remove access.
WorkspaceYour plan, workspace ID, quotas, and resolved feature flags — read-only. The Danger Zone (Owner only) holds data export, deactivate, and delete.
API KeysMint operator-side API keys (separate from customer-facing keys). Rotate, scope, revoke.
SSOSAML / OIDC configuration for federated login. Map IdP groups to Aforo roles.
RolesDefine custom roles that inherit a system role and narrow its permissions (Owner-only). Assign them to members.
Session PoliciesPer-role session TTL, idle timeout, and concurrent-session limits.
Audit LogImmutable record of operator actions. Filter by actor, time, target. Export CSV for a security review.
Access ReviewsPeriodic access-certification campaigns — review who has which role and attest or revoke.
CategoriesCustom product categories your team uses to organize the catalog.
Your FeaturesPer-workspace view of which platform features are enabled, with stage labels (GA / BETA / ALPHA).
Active SessionsSee every active operator session. Force-logout a session if you suspect a stolen token.
Admin AlertsInternal alert routing — which operator email addresses receive which alert family.
INFO
SCIM auto-provisioning lives one section over in . SSO authenticates an existing user; SCIM creates and removes the user from your IdP automatically.

Who can do what#

Workspace Admin itself is role-gated. Common roles and what they can change here:

RoleCan modify
OwnerEvery tab. Only role that can transfer ownership or delete the workspace.
AdminEvery tab except Owner-only destructive actions (workspace delete, ownership transfer).
DeveloperAPI Keys (own keys), Audit Log (read-only). Cannot invite members or change SSO.
Billing AdminWorkspace (billing fields), Audit Log (read). Read-only on Members.
MemberAudit Log (own actions only). Read-only on most tabs.
ViewerRead-only across tabs. No exports, no PII, no writes.

When SSO is on

Roles are mapped from IdP groups. Changing a user's role in Workspace Admin only sticks until the next IdP sync — for SSO-managed workspaces, change the group in your IdP and let SCIM / next-login resolve the role.

  • Governance → SCIM Provisioning — auto-provision portal users from your IdP.
  • Governance → Workspace Switching — one sign-in, every workspace you belong to.
  • Developer → Developer Hub — customer-facing API keys (separate from operator keys).
  • Customer Success → Alerts & Notifications — outbound event delivery (separate from Admin Alerts, which is internal operator email).