Workspaces: Create, Invite & Switch
One sign-in, every workspace you belong to. How to create a workspace, invite teammates into it, move between workspaces, and why a new seat shows up without logging in again.
What a workspace is#
A workspace is the unit you actually work inside — its own products, rate plans, customers, invoices, and usage data. Everything in Aforo is isolated by workspace: data in one workspace is never visible from another.
An organization is the parent that can own several workspaces. SmartAI is one organization; its IT and Product Eng workspaces are two separate, fully-isolated environments under it. You sign in once and reach every workspace you have a seat in — across organizations, not just one.
How your access is decided#
When the console asks “which workspaces can this person reach, and with what role?”, it does not read a baked-in list from your sign-in token. It resolves the answer live from the database, keyed on your identity, every time the picker loads. Two things grant a seat:
- A direct workspace membership. You are a member of that specific workspace with a role — Owner, Admin, Billing admin, and so on.
- An organization membership you inherit down. If you are an org owner or org admin, you inherit access to every workspace that organization owns. An org owner lands as Owner in each; an org admin lands as Admin.
Because the list is resolved live and keyed on you, two things follow that matter in day-to-day use: a seat granted a minute ago appears on your next picker load, and a seat revoked a minute ago disappears just as fast. Nothing is “stuck” in an old token.
Switching between workspaces#
You can switch as often as you like, in either direction. There are two routes to the same place, and which one you reach for depends on where you are when the urge strikes.
From inside a workspace — the header menu#
Open your profile menu in the top-right of any workspace and choose Switch Workspace. That takes you to your account home, where every workspace you belong to is listed; pick one and you land inside it.
From a fresh sign-in — the workspace picker#
When you sign in and you are not already pointed at a specific workspace, Aforo shows the picker (below). It is the same destination the header menu sends you to. Each switch issues a fresh, single-use handoff so the move is clean — there is no shared link to leak and no stale code to reuse.
The workspace picker#
The picker groups your workspaces under the organization that owns them. Here is exactly what a SmartAI admin sees — two workspaces under SmartAI plus a Finance workspace under GlobalAI they also have a seat in:
Reading a row, left to right:
- Organization header (SmartAI, GlobalAI) — the parent. The chip beside it (Org admin) is your role over the organization, if any. SmartAI shows it; GlobalAI does not, because here you only hold a single-workspace seat.
- Workspace name + slug (IT · smartai-it) — the workspace you enter when you click Open.
- Your role in that workspace (Owner, Admin, Billing admin) — what you can do once inside. The same person can be Owner in one workspace and Billing admin in another.
Creating a workspace#
Need a clean, separate space — a second environment, a new business unit, or a dedicated workspace for a specific customer? An org owner or org admin provisions a new workspace from the organization console. It comes up fully isolated under your organization — its own products, rate plans, customers, and invoices, sharing nothing with your other workspaces.
- Open the Organization console at /organization and select the Workspaces tab. You need to be an org owner or org admin; other roles see the list read-only.
- Choose New workspace, give it a name, and create it.
- Aforo provisions the workspace and seeds its default billable units, so it’s ready for its own catalog and pricing right away.
Closing a workspace or organization#
Aforo exposes three “Danger Zone” consoles, and they read as duplicates until you know each one’s scope. They aren’t — each acts at a different level of the tenant hierarchy, and each is reachable from a different place in the sidebar. The right one depends on what you’re trying to end.
| What ends | Where | Reversible? | Role required |
|---|---|---|---|
| Every organization you own in one batch — each parent org + every workspace under it. Orgs where you’re only an invited admin are untouched. Your personal login stays intact. | Profile menu → Account & Security → Danger Zone. | Yes — 30-day grace. One email restore link cancels the whole batch. | Org OWNER role. |
| A single workspace — its products, rate plans, customers, invoices, and members lose access. Sibling workspaces under the same org are untouched. | Profile menu → Workspace Admin → Workspace tab → Danger Zone. | Yes — 30-day grace. Deactivate has an in-page Reactivate button; Delete emails a restore link to all workspace owners. | Workspace OWNER. |
| The whole organization — every workspace under it loses access at once. | Sidebar → Governance → Organization → Organization status. | Suspend is reversible via Restore. Archive is permanent — contact support to recover. | Org owner or org admin. |
Two more things worth knowing before you act:
- Deactivate is not the same as Delete. On a workspace, Deactivate is a soft-stop — members lose access, the workspace comes back with the in-page Reactivate button, and the data is preserved during the grace window. Delete schedules permanent removal across every Aforo service — a restore link is emailed to all workspace owners as the only recovery path.
- Aforo blocks a workspace close on active billing. If the workspace has any active subscriptions or unsettled invoices, the pre-flight guard on Deactivate and Delete surfaces the blockers before you type the confirmation phrase. Resolve those first; Aforo re-runs the same guard server-side.
- Single-workspace organizations. If your organization contains exactly one workspace, archiving the org effectively ends that workspace too. In that case, closing the workspace directly (with the 30-day grace + email restore path) is usually what you actually want — the Organization status page calls this out inline when it detects the single-workspace shape.
Giving someone access#
Say a SmartAI admin (call them A) wants a colleague (B) to work in a SmartAI workspace. B will see and switch into that workspace once their invite is bound to their identity — not just their email address. There are two ways to invite, and they bind at different moments.
| Invite path | When B gains access | What B sees |
|---|---|---|
| Organization-level — add B as an org member | Automatically, on B’s first sign-in. Aforo matches the invite’s email to B’s verified login and binds it to their identity in one step. | Every workspace that organization owns, at the inherited role. |
| Workspace-level — add B as a member of one workspace | Once B joins the workspace through the team-membership flow, which binds the seat to B’s identity. This is the normal “accept the invite” path. | That one workspace, at the role you assigned (Admin, Billing admin, …). |
Invite to the whole organization#
Best when a teammate should reach every workspace your organization owns.
- Open the Organization console (/organization) → Members tab. You need to be an org owner or org admin.
- Choose Add member, enter their email, and pick an organization role.
- Send. They show as Invited; on their first sign-in the seat binds to their account and they inherit access to every workspace the organization owns.
Invite to a single workspace#
Best when access should stay scoped to one workspace — a contractor on one project, a teammate who only needs one environment.
- Switch into the target workspace, open the Workspace Admin, and select the Members tab. You need to be the workspace Owner.
- Invite by email and assign a workspace role — Admin, Billing admin, Developer, or Viewer.
- Send. The seat binds when they join through the membership flow; until then it’s pending and the workspace won’t appear in their picker.
Roles reference#
Roles are assigned when you invite, and a person can hold a different role in each workspace. Workspace roles govern what you can do inside a workspace; organization roles govern the parent and inherit down.
| Workspace role | Can typically… |
|---|---|
| Owner | Everything in the workspace, including inviting and removing members. |
| Admin | Manage products, pricing, customers, and most settings. |
| Billing admin | Focus on invoices, billing, and revenue surfaces. |
| Developer | Build and integrate — metrics, ingestion, and developer tools. |
| Viewer | Read-only access; cannot invite or change settings. |
| Organization role | What it grants |
|---|---|
| Org owner | Full control of the organization; lands as Owner in every workspace it owns. |
| Org admin | Administer the organization and its members; lands as Admin in every workspace it owns. |
Do I need to log in again to see a new workspace?#
No. The picker list is read live from the database against your identity, not from your sign-in token. The moment a new seat is granted — you provision a workspace, an admin adds you, an org invite binds — it shows up on your next picker load. No sign-out, no token refresh, no service restart.
The only nuance: the picker caches its result for about 30 seconds to stay snappy, so a brand-new seat appears on the next refresh rather than the same instant. That is a refresh, not a re-login. And switching into a workspace never re-authenticates you — the handoff carries your existing session; only the workspace context changes.
What carries over, and what resets#
A switch changes which workspace you are operating in — so the console deliberately clears anything tied to the workspace you just left, while keeping anything tied to you.
| Carries over (tied to you) | Resets (tied to the workspace) |
|---|---|
| Your sign-in session — you stay logged in. | The workspace your requests are scoped to. |
| Your identity and the set of workspaces you can reach. | Cached data from the old workspace — flushed on switch so nothing bleeds across. |
| Your account-level profile. | Your effective role — it is per-workspace, so it may differ on the other side. |
Enumerate your workspaces in code#
Switching is a console action — you click, you do not script it. But if you are automating an internal tool and want the list of workspaces your session can reach, the console reads it from one endpoint. Call it with your operator session token:
The response mirrors the picker exactly — organizations, each with its workspaces and your role:
What workspace switching does not do#
Switching changes where you stand; it never merges or shares data. Worth being explicit, because the single sign-in can make it feel like the workspaces are connected under the hood — they are not.
- It does not pool data across workspaces. Products, customers, invoices, and usage stay isolated per workspace. A switch points you at one workspace at a time; there is no combined view.
- It does not copy your role across. Being Owner in IT does not make you Owner in Product Eng. Each seat carries its own role.
- It is not a way to grant access. You can only switch into a workspace you already have a seat in. To add a teammate, use an invite (see Giving someone access).
- A teammate working in your workspace is operating under that workspace’s isolation boundary — intended shared access for a shared workspace, not a cross-workspace leak.
Troubleshooting#
| Symptom | Cause | Fix |
|---|---|---|
| A workspace I was just given doesn’t appear in the picker. | The ~30-second picker cache hasn’t refreshed yet, or an invite hasn’t bound to your identity. | Reload the picker. If it was a workspace-level invite, make sure you joined through the membership flow — that’s what binds the seat. |
| A teammate I invited can’t see the workspace. | Their invite is still keyed on their email, not their account. | Org invites bind on their first sign-in. Workspace invites bind when they join the workspace. Confirm they completed that step. |
| After switching, I briefly saw the old workspace’s data. | A cached screen rendered before the switch flushed it. | Reload once; the cache is cleared on switch and the new workspace loads fresh. Report it if it persists. |
| “Switch Workspace” sends me somewhere I can’t pick a workspace. | You may have a seat in only one workspace, so there is nothing to choose between. | That’s expected with a single seat. Ask an org admin for additional workspace access if you need it. |
| I got handed back to the picker after clicking a workspace. | The one-time handoff code was already used or expired. | Pick the workspace again — a fresh code is minted each time. Repeated failures mean the seat may have been revoked. |
Managing who belongs where is the other half of this story — see to drive membership from your identity provider, so seats appear and disappear in lockstep with your directory.