Workspace and projects
Understand resource ownership and manage workspace identity
The workspace owns membership, API keys, plugin installations, data endpoints and administrative settings. A project inside it supplies execution and ontology context for pipelines, queries and predictions. The same endpoint can be referenced by multiple projects without copying its connection or credentials.
Requirements
You need a Semogram account with workspace access. Changing the workspace name/slug requires Owner; other administrative controls accept Owner or Administrator as documented. An API key belongs to one workspace and cannot gain access to another by replacing a URL ID.
| Resource | Scope | Consequence |
|---|---|---|
| Member or API key | Workspace | Its access is evaluated in this workspace |
| Plugin installation | Workspace | Shared connection/capability configuration |
| Data endpoint | Workspace | Shared named target through an installed capability |
| Pipeline, ontology, query or forecaster | Project | Must belong to the selected project/workspace |
| Write policy | Workspace or project | Its revision can be used only within its permitted scope |
Human project access follows workspace membership in the current membership model. The API-key project allowlist is a separate restriction; do not describe it as a per-member project-role editor.
Change workspace details
Open Workspace settings → Workspace details, edit Name or Slug and select Save changes. Read back the workspace picker/settings and check consumers that use the old slug. Use a meaningful name such as Factory operations and a URL-safe identifier such as factory-operations.
The UUID is distinct from the slug. Workspace MCP URLs require the workspace UUID; a name or slug does not substitute for it. Changing a display name does not create a new workspace.
Inspect through supported interfaces
The public API exposes GET /api/v1/organization with org:read. MCP exposes workspace_get with projects:read, and project_list/project_get for project discovery. These identify the authenticated workspace/resources; they do not rename the workspace.
Inspect the authenticated workspace and list its projects. Explain which plugins and endpoints are shared workspace resources and which project contains my Maintenance query. Do not create or change anything.Workspace creation and detail editing are signed-in app workflows. Do not treat their internal session routes as public API-key actions. See getting started for initial creation.
Changes with wider impact
An unrestricted key covers all current and future projects. A restricted key covers only its selected IDs. Workspace-wide policy/settings changes can affect several projects; inspect their consumers before changing them. For deletion, use the separate workspace lifecycle guide.