Workspace administration
Teams and organizations
Separate personal application collaborators from governed organization workspaces, roles, invitations, and applications.
Ownership models
| Workspace | Use | Access boundary |
|---|---|---|
| Personal application | A project owned by one developer account. | Invite collaborators to that application only. |
| Organization workspace | An approved company, institution, agency, or issuing body. | Organization roles govern members and multiple applications. |
Organization approval
- 1Submit legal and registration details
- 2UnifyID creates a restricted pending workspace
- 3An administrator reviews the organization and representative
- 4Approval activates workspace access
- 5Owners invite members and create applications
Pending and rejected organizations cannot manage members or organization applications. Review decisions are made in the UnifyID admin system and recorded in the audit trail.
Invitations
Invitations are bound to the recipient email, expire, and require the recipient to authenticate the matching verified UnifyID account. A six-digit email code confirms possession before access is created.
Role boundaries
Application roles are scoped to one personal application. Organization roles apply only inside one approved workspace. Owners should grant the smallest role needed and regularly remove inactive access.
Operational checklist
Apply these controls throughout the membership lifecycle to keep privileged access attributable, recoverable, and current.
Require MFA for every owner and administrator account.
Give each person a named account. Never share sign-in credentials.
Review pending invitations regularly and cancel any that are no longer required.
Keep at least one active organization owner to prevent administrative lockout.
Suspend or change access as soon as a person’s responsibilities change.
Reassess application credentials and rotate affected secrets after team changes.