Workspace Admin
Workspace administration — manage members and roles, define custom roles, view workspace config, mint API keys, configure SSO, set session policies, run access reviews, audit actions, manage categories and feature flags, revoke sessions, and set admin alerts.
Workspace Admin
The Workspace Admin (opened from the workspace menu at the bottom of the sidebar) is where you administer your Aforo workspace. It has twelve tabs.
Members
Invite, re-role, and remove team members. Roles: OWNER, ADMIN, BILLING_ADMIN, DEVELOPER, MEMBER, VIEWER. Member status is ACTIVE, INVITED, or REMOVED.
Workspace
View your plan, workspace ID, quotas, and resolved feature flags.
Danger Zone (OWNER only)
Three self-service actions for closing this workspace. All three affect only this workspace — they never touch your parent organization or your other workspaces.
Deactivate and Delete are both blocked when the workspace has active subscriptions or unsettled invoices — resolve those first. Aforo re-checks server-side; the pre-flight is a UX gate.
Three Danger Zones, three scopes. Don’t come here to close your parent organization, and don’t come here to close your personal user account.
- This page (Workspace Admin → Workspace) closes only this workspace.
- Governance → Organization → Organization status closes the whole organization + every workspace under it (Suspend / Archive). Org owners / org admins only.
- Profile → Account & Security → Danger Zone bulk-closes every organization you own (with the same 30-day grace + email restore). Organizations where you’re only an invited admin are untouched. Your personal Aforo login is preserved so you can start a fresh organization during the grace window.
If your organization contains exactly one workspace, archiving the org effectively ends that workspace too. In that case, closing the workspace here (with the 30-day grace + email restore) is usually what you actually want.
API Keys
Mint and revoke operator API keys with scopes (e.g. headless:read, catalog:write, admin:all) and an optional expiry. The raw key is shown once at creation. Revoking also propagates revocation to connected gateways.
SSO
Configure enterprise single sign-on — SAML 2.0 or OIDC (provider, domain, IdP entity ID / issuer URL, metadata URL). Status is ACTIVE, PENDING, or ERROR. Test SSO validates the connection.
Roles
Define custom roles that inherit one of the six built-in roles (OWNER, ADMIN, BILLING_ADMIN, DEVELOPER, MEMBER, VIEWER) and narrow it — grant extra permissions or deny specific ones, with three starter templates. Custom roles are narrow-only (they can't exceed the base role) and owner-only. See Roles & Permissions for the full guide.
Session Policies
Set per-role session limits — maximum idle time, maximum session lifetime, and the number of concurrent sessions a role may hold. Owner-only.
Audit Log
A paginated, filterable record of administrative actions — actor, action, target, timestamp, and details.
Access Reviews
A periodic (monthly or quarterly) access certification the owner attests: who holds access, role changes in the last 90 days, and dormant API keys. Overdue reviews escalate so certification doesn't depend on someone remembering to run it. Owner-only. See Roles & Permissions.
Categories
Manage the product/community categories (name, icon, description, color) used to organize the catalog and community.
Your Features
A read-only view of your feature flags and their rollout stage (GA, BETA, ALPHA, DARK, KILLED). Flags are managed centrally in Aforo Control Tower; this tab shows what's enabled for your workspace tier.
Active Sessions
View and selectively revoke active end-customer sessions (by JWT ID), filterable by status (ACTIVE, REVOKED, EXPIRED), customer, and OAuth client.
Admin Alerts
Configure webhooks for critical operational events (payment failures, reconciliation mismatches, usage spikes, invoice-generation failures), with a threshold and an enable toggle. Test Alert sends a sample payload; View Deliveries shows the webhook delivery log.
Admin Alerts notify your operators about infrastructure events. Customer-facing event notifications are configured under Alerts & Notifications.