# Workspaces, roles & teams

A workspace (called an organization in some API paths) is the unit of billing and access: it has one plan, one Balance, one team and its own API keys, audit log and settings. Signing up creates your personal workspace; create more from the workspace switcher. How many you can own depends on the best plan among them.

Free limits are per person, across all your free workspaces. Every paid workspace has its own limits. A second free workspace shares the first one's allowance: every Hobby count (projects, functions, databases, team members, emails and the rest) is the total across the free workspaces its owner owns.

## Roles

| Role | Can |
| --- | --- |
| Owner | Everything, including the plan, cards, the Balance, spending limits, withdrawals and refunds, and deleting the workspace. |
| Admin | Members and invitations, API keys, workspace settings (CDN, Shield, AI Gateway models, mail controls), the audit log, reading billing, deleting projects. |
| Developer | Create, change and delete resources and deployments; read environment variables, function source and stream keys. |
| Viewer | Read only — no environment variables, secrets or function source. |

## Team members

- Admins invite by email. The invitation is emailed, and accepting it needs a verified email at the invited address.
- Seats per plan: 3 hobby, 10 pro, 100 enterprise. Pending invitations hold a seat; a full workspace answers 402 `plan_limit`, and accepting re-checks. On Hobby the seats are people across all the owner's free workspaces.
- Removing a member lists the API keys they created so you can revoke them.

## What lives where

- In the workspace: the plan, Balance and cards, members, API keys, the audit log, domains bought, repos, the mail log and settings, and CDN, Shield and AI Gateway settings.
- In a project: its site or app, environment variables, custom domains, and its databases, buckets, functions, vector collections, memory stores, agents, auth pool, payment account and media.

## Deleting a workspace or account

- Deleting a workspace cancels its subscription immediately (no proration refund) and tears down every project.
- It is refused while the workspace owns unexpired bought domains (transfer them out, or turn off auto-renew and let them lapse), has a domain transfer, refund or Balance top-up in progress, or holds project earnings.
- A positive Balance is given up, not refunded, and only when you say so: send `{ "confirmForfeit": true }` (the first answer is 409 `confirm_forfeit_required`).
- Deleting your account (`DELETE /api/auth/me { password, confirmForfeit? }`) applies the same rules to every workspace it removes.

## Reference

**REST**

```http
GET    /api/orgs                        # your workspaces
POST   /api/orgs                        { "name" }                              # browser session
GET    /api/orgs/:id/members · PATCH · DELETE                                    # admin to change
POST   /api/orgs/:id/invitations        { "email", "role": "admin"|"developer"|"viewer" }
DELETE /api/orgs/:id                    { "confirmForfeit"? }                   # owner
```
