Stable

Workspaces: concept and first steps

What a workspace is, what it contains, when to create a separate one, and how to set up members, groups, apps and access.

Steps

Follow these in order.

  1. 01Choose the right boundaryUse one workspace for one company, team or client boundary. Create another one when ownership, billing, logs or security rules must be separate.
  2. 02Add members and rolesInvite users, assign owner, admin, member or billing roles, and review access regularly.
  3. 03Create groupsUse groups for stable teams so app access is managed once for many users.
  4. 04Connect the private networkCreate an outbound connector in the workspace and run it where the internal app is reachable.
  5. 05Publish an appDefine the app address, connector, internal service address, session lifetime and basic access rule.
  6. 06Review billing and logsPlans, seats, add-ons, payment operations, audit logs and blocked events belong to the workspace.

Reference

Implementation details for setup and review.

What a workspace isA workspace is the main BusinessProxy container for one company, team or customer. It keeps members, roles, groups, apps, connectors, domains, billing and event logs together under one data and access boundary.No image
  • A user can belong to several workspaces, but each workspace keeps its own apps, groups, domains, billing and logs.
When to create a separate workspaceCreate a separate workspace when a customer, legal entity, data owner, payment owner, private network or security policy must be separated. Do not create a new workspace only for an internal department if groups and access rules are enough.
Members, roles and groupsMembers are BusinessProxy users inside the workspace. Owners and admins manage settings and access; members use assigned apps; billing users work with payment records. Groups help assign app access to a team instead of every user one by one.No image
  • Group names can use any language; the internal technical identifier is hidden from users.
Connectors, apps and domainsAn outbound connector runs in the customer network and reaches the internal app. The published app then receives a BusinessProxy system address or a verified customer domain. Domains, certificates and aliases belong to the workspace that verified them.No image
Basic setup flow
  • Create or choose the workspace, then confirm that the correct workspace name is shown in the dashboard.
  • Invite members, assign roles and create groups for stable teams.
  • Create a connector, store the one-time token safely and run the connector where the internal app is reachable.
  • Publish the app, set the session lifetime and configure group allow or deny rules.
  • Open the app from the app portal, then review billing, audit logs and blocked events.