03 — Working with other people
What you will have at the end: somebody else in your organization, holding a role you chose in one workspace and nothing in the others, with their cursor moving next to yours in the same document.
What you need: a free account, an organization you own, and one other person's email address. They will have to sign in at some point for any of it to take effect.
Two levels, and only one of them grants access
Everything about permissions here falls out of a shape you set up once:
- An organization is who you work with. People belong to it.
- A workspace is what you work on. It belongs to exactly one organization.
The part that surprises everybody the first time: belonging to the organization gives somebody nothing. Not read access, not a list of your workspaces, nothing. What it does is make them shareable — somebody you are now allowed to hand a workspace role to.
1. Invite somebody to the organization
Open the organization menu (top right) and choose Organization
configuration…, which opens as a tab, and find its Members section.
Ctrl+Shift+P → Open Organization Configuration gets you to the same place.
Type their email address, pick Member or Owner, and click Invite.
- Member — belongs to the organization, can create workspaces in it, and can be given a role in yours.
- Owner — all of that, plus invites and removals, agents, and deleting the organization itself. Renaming one needs an entitled account, so that command may sit there greyed out even for you.
One thing to know before you close the dialog.
Nothing is emailed (yet). The app says "Invite created — a message was copied to your clipboard to send them", and that is exactly what happened: sending it is your job. An invite that was never sent looks identical to one that was ignored.
2. What happens on their side
- If they already have an account, they are a member the next time they load the app.
- If they have never signed in, the invite waits, and is claimed automatically the first time they sign in with that address. No second step for either of you.
There is no other way in. Until somebody has authenticated at least once there is no account for a membership to attach to, so an address alone cannot be added.
3. Give them a role in a workspace
In the explorer's workspace list, hover the workspace and open its ⋮ actions menu, then choose Settings. The dialog opens on a Members section: "Choose what each organization member can do with this workspace."
Every other organization member is listed with a dropdown, and everyone starts at No access. Pick Viewer, Editor or Admin. You will not find yourself in the list, or whoever created the workspace — neither is somebody you can grant anything to.
It takes effect immediately — there is nothing for them to accept. If they have the app open, the workspace appears in their sidebar.
Only somebody in this workspace's own organization can be given a role. The picker lists nobody else, and the database refuses it even if you go around the picker.
4. What each role can actually do
| Viewer | Editor | Admin | Owner | |
|---|---|---|---|---|
| Read every document in the workspace | ✅ | ✅ | ✅ | ✅ |
| Comment, reply, react, resolve | ✅ | ✅ | ✅ | ✅ |
| Write documents, create files, upload images | ✅ | ✅ | ✅ | |
| Manage who else is in the workspace, and its share links | ✅ | ✅ | ||
| Rename or delete the workspace | ✅ |
The first row is about people, and for a person it has no exceptions. An agent is the one reader it does not hold for: no agent can see into another agent's private folder, whatever role it has. Tutorial 02 sets that up.
Two of those rows are worth reading twice.
A viewer comments. Reading and commenting are deliberately the same tier: somebody you brought in to look at something can say what they think about it without you having to hand them the ability to rewrite it.
Nobody inherits the last row. Owner is not one of the choices in that dropdown — it starts as whoever created the workspace, and renaming or deleting it is theirs alone. An admin you trust with the whole share list still cannot delete the thing. Ownership moves in exactly one situation, and nobody picks it: when somebody leaves the organization — or is removed from it — the workspaces they owned pass to an organization owner rather than leaving with them.
And one for when you get there: an agent can be a viewer or an editor, never an admin. Admin is authority over who reaches the workspace and what leaves it, which is not document work. The dropdown tells you so instead of accepting the choice and failing the write.
5. Watch them arrive
Now the part you can only see with two of you in it. Open the same document and have them type.
- Their cursor is in your text, in their own color, with their name on it. Every selection they hold is drawn, not just one, so a multi-cursor edit reads as what it is.
- A count in the status bar, bottom right, with a green dot while you are connected. Click it for Online in this workspace — who is here, whatever file they have open. An agent's name carries a 🤖.
- Dots in the file explorer, against the files people currently have open.
Nobody has to save for any of this: the text arrives as it is typed. Saving is what the ● dirty dot is about, and when one of you saves it clears for everyone.
A cursor means "working", not "connected". It fades after a couple of minutes of nothing and comes back the moment they type or move. So a quiet document is genuinely quiet, rather than crowded with people who left a tab open at lunch.
6. Taking it back
One workspace. Set their dropdown back to No access in the workspace's own configuration tab — the ⋮ beside it in the sidebar, then Configuration. That workspace leaves their sidebar; everything else is untouched.
All of it. Remove them from the Members section of organization configuration. Every workspace role they held anywhere in the organization goes with the membership — including in workspaces you do not administer yourself.
Themselves. Anybody can use Leave organization…, in that page's danger zone or beside their own name in the member list.
Three things stop a departure, and they do not all look the same:
- The last owner cannot leave. An organization nobody can administer is unrecoverable, so the app says so and names the way out: invite another owner first, or delete the organization.
- Nobody can leave their last organization. Everyone belongs to at least one, so the departure that would leave you with none is refused.
- Your own personal organization — the one created with your account, where your own work lives — simply does not offer the option. There is no refusal to read, because there is nothing to click.
What you have now
An organization with somebody else in it, one workspace they can reach with exactly the authority you chose, and a document where each of you can see what the other is doing while they do it.
The shape holds as you add people: they belong to the organization, access is granted per workspace, and those stay two separate decisions.