Canonical page: https://tellenze.com/help/workspace-admin

# Manage workspace access and settings

Manage members, invitations, feature availability, shared defaults, and administrative settings.

## Find workspace administration

Administrators open **Admin** from the workspace navigation. The main tabs are **Team**, **Settings**, **Workflows**, **Work types**, and **Integrations**, when available. The three-dot **More admin sections** menu contains **Usage**, **Agent reactions**, **Insights**, **Automations**, **Templates**, **Billing**, and **Domains** when enabled for the workspace. The menu highlights the current section when it is one of these secondary pages.

Admin uses the same spaced icon tabs as personal settings. Desktop tabs wrap when needed; on smaller screens, swipe the main tabs while the three-dot menu stays visible. Use Left/Right or Home/End between main tabs, Up/Down or Home/End inside the menu, and Escape to close the menu.

**Team** shows members, pending invitations, and headline counts for active members, active projects, open work, and MCP connections. **Settings** contains workspace preferences, including work estimation.

Personal settings are separate. Members manage their own preferences, notifications, briefing preferences, Machine profiles, MCP connections, and personal Agent reaction setup. Admin controls govern shared workspace behavior and access.

Home’s onboarding includes administrator lessons for creating a project and inviting teammates. Progress belongs to each member, including existing accounts, on every installation. Promotion adds the admin checkpoints while preserving shared progress; demotion removes admin-only checkpoints. Members can resume or replay their lessons under **Account settings → Preferences → Onboarding**.

## Check workspace usage against your plan

Open **Admin → More admin sections → Usage** to compare current usage with your workspace's effective plan allowances. Each category shows its usage, allowance and remaining capacity, with **Near limit**, **At limit** or **Over limit** where applicable. **Refresh usage** reloads the snapshot; **Manage plan** opens Billing. Only active workspace administrators can view this page.

- **Human seats** includes active members and unique usable pending invitations. Expired and revoked invitations do not reserve capacity.
- **Connected agents** counts nonrevoked MCP connections and paired companions. There is no plan-based count limit; third-party provider charges remain separate.
- **Projects** and **Work items** count all retained records, including archived and completed work. Archiving does not release capacity.
- **Custom Forms** counts nonarchived drafts, published forms, and paused forms. Archiving releases a form slot and retains its responses. Creation starts at Starter; see [Custom Forms](https://tellenze.com/help/custom-forms) for limits and how existing published forms behave after a downgrade.
- **Storage** counts retained attachment files and App icons, including archived attachments. Shared attachment copies count once. Values use binary units such as MiB and GiB.
- **Custom domains** counts reserved custom addresses, including pending and disabled addresses. Removed addresses do not count; domain feature availability remains separate from the plan allowance.
- **Automation runs** and **Looper requests** include completed usage and reservations for operations whose outcomes are not yet confirmed. Looper chat, briefings and assistant insights share the allowance; external agents using their own provider do not consume it.

Monthly usage resets at **00:00 UTC on the first day of each calendar month**, independently of the subscription's billing cycle. The page shows the current period and next reset. Capacity allowances do not reset monthly. Limits reflect the assigned plan revision, subscribed seats and agreed overrides. If a verified paid period has ended, the page explains that effective Free allowances and any overrides apply.

**Unlimited** means no plan cap, while feature availability and operational safeguards still apply. A zero allowance is a real limit. Missing workspace registration or enrollment is shown as unavailable, and disabled monthly metering is never presented as measured zero usage. Reaching an enforced limit pauses new usage in that category and preserves existing work.

## Connect tools or bring existing work

**Admin → Integrations** includes **Connections**, **Imports** and **Sign-in methods**. **Connections** is the catalogue for ongoing tool connections; GitLab is available, and enabled publishing integrations appear under **Publishing**. Providers marked **Coming soon** cannot be connected yet. **Imports** is for bringing existing projects and tasks into Tellenze from another tool.

**Emergent Newsroom** appears only when your workspace operator has enabled it. Its page shows whether setup is ready and explains how to share an outcome. The operator manages credentials; incomplete setup keeps task handoffs unavailable. Disabling the integration preserves existing draft records and delivery history.

**Publishing** also lists WordPress, Ghost, Webflow, Hashnode and DEV Community as **Coming soon**. These planned integrations will help prepare outcome drafts for websites and blogs. You can browse and search their cards, but cannot connect an account or send content to them yet.

**CSV file** is available for a reviewed, one-time migration. Jira, Asana, Trello, monday.com, Basecamp, ClickUp and Todoist remain **Coming soon**; those cards do not connect to a provider or import data. Jira appears in both tabs because importing existing work and maintaining an ongoing connection serve different purposes.

## Set up email powerups

Open **Admin → Integrations → Gmail** or **SMTP** for that provider's configuration page. Enable each provider before members can connect or send; both start disabled. Both Gmail and SMTP support personal and shared workspace connections. Members choose a provider in **Settings → Integrations** to manage personal connections; administrators manage shared ones on the corresponding admin page. Members can choose a permitted sending connection on work items they are allowed to update. Disabling a provider stops connections and sending while keeping drafts and history.

Workspace administrators configure Gmail directly on this page. Under **Google OAuth application**, enter the **Google client ID** and **Google client secret** from your own Google Cloud project. Enable the Gmail API, create a web OAuth client, and copy the displayed **Authorized redirect URI** into that client's redirect URI list. Complete the consent setup for the intended accounts, then choose **Save Google credentials**. The credentials are encrypted and scoped to this workspace; the saved secret is never displayed. Leave the secret blank to keep it when saving unchanged credentials. Changing credentials requires existing Gmail accounts to reconnect and keeps their email history.

Enable **Gmail for this workspace**, then choose **Connect Gmail** to authorize a shared sending mailbox. Members can connect their own Gmail accounts from **Settings → Integrations** once workspace setup is complete and Gmail is enabled. These connections use the workspace's Google OAuth application. Connecting Gmail for email powerups does not grant inbox reading or import email into Signals.

For SMTP, enter the provider's server, port, TLS mode, username, password, sender address and sender name. Use credentials intended for sending email and the sender address allowed by that provider. Saved secrets are encrypted and are not shown again. Saving connection settings does not send an email or prove that a provider will accept delivery.

The SMTP sender can include variables. For example, `e_{username}+{workItemId}@my-company.com` uses the sending member's profile handle and work item ID. Available variables are `{username}`, `{memberId}`, `{workItemId}`, `{projectKey}` and `{teamKey}`; `{memberName}` also works in the display name. Project/team variables need the matching work-item owner. Keep the domain after `@` fixed. The setup preview uses sample values; the draft shows the actual sender for review. Your provider must permit the expanded sender addresses.

On the **SMTP** page, choose **Add SMTP connection** for each sender you need, such as Support or Billing. Give each connection a recognizable name; members see that name when selecting **Send from** in a powerup. Use a connection's **Edit** action to change only that sender, leaving its password blank to keep the saved password. Enabling, disabling or disconnecting one connection leaves the others unchanged. Members can also save multiple personal SMTP connections on their own SMTP page.

Members use `/send-email` or `/send-gmail-email` in a work item's **Conversation**, review the generated draft, and explicitly send it. See [Email powerups](https://tellenze.com/help/work-items#send-an-email-with-a-powerup) for editing recipients, CC, BCC, subject and message. Disconnecting prevents future sends while preserving conversation history. An uncertain send needs a check of the provider's sent mail or logs before another submission.

## Import work from CSV

Open **Admin → Integrations → Imports → CSV file**. Importing requires an active administrator with permission to create work in the destination Project or Team. Existing membership and Required Context rules still apply. Importing never invites users or grants access.

1. Download the template, or prepare a CSV export from your source tool. Choose a destination and a source namespace: a required, stable name for that source list, such as `operations-roadmap`, reused on later uploads for duplicate detection.
2. Upload a file of at most **2 MB, 500 data rows and 100 columns**. Inspect the detected encoding and delimiter, then review the column mapping. Only supported fields are imported; extra headers do not create custom fields.
3. Map source stages, assignees and labels to available destination values. Unknown or ambiguous values need an explicit choice. Review titles, dates and parent references in the row preview. Correct the source file or mappings and preview again, or explicitly skip invalid rows.
4. Confirm the reviewed preview to create work. Each request processes at most **50 rows**. Choose **Continue import** for another batch, or reopen the saved run to resume later. Cancellation stops remaining rows and preserves items already created.
5. Inspect the created, skipped and failed counts. Failed rows include a reason; resolve it before resuming or upload a corrected file using the same source namespace and IDs.

After reading the file, **Preview import** requires a destination, a valid source namespace, a mapped Title column and loaded destination settings. The panel beside the button lists anything missing; select a message to jump to the field or retry control. You can leave recognized values on **Match automatically if recognized**. The preview reports unresolved row values before you explicitly confirm an import.

Use `source_id` for the original stable row identifier and `parent_id` for another row's source identifier. Reusing a source ID within the same destination and namespace detects an already imported item; it does not overwrite its current title, assignment or other manual edits. Separate source lists should use separate namespaces. Without source IDs, duplicate detection covers an identical file and row position only. Editing or reordering that file can create new items on reupload. Identical-looking rows are not silently merged.

The importer accepts comma, semicolon or tab delimiters and UTF-8, UTF-16LE, UTF-16BE or Windows-1252 text. UTF-16 detection needs its byte-order marker; choose the encoding explicitly when the file has none. File format options let you override detection or indicate that the file has no header. Headers must be unique and non-empty. Binary control characters are rejected.

Assignees and labels accept JSON arrays, such as `["person@example.com"]`, or semicolon-separated values. JSON arrays preserve punctuation and spaces inside names. Due dates and benefit-period dates use `YYYY-MM-DD`; source creation and completion dates also accept ISO timestamps such as `2026-09-27T10:00:00Z`. A timestamp without an offset is interpreted as UTC. Estimates must use the destination workspace's current scale; change or omit estimates from a different scale before importing. The downloaded template lists the supported columns.

Formula-like values and HTML are treated as text. Tellenze exports include a format marker so spreadsheet-safe escaping can be reversed during import; keep it with the file. A mapped stage key takes precedence over the status column for rows where it has a value.

Source dates and metadata remain separate from the importing member and actual import time. A completed source item records an existing historical completion; it does not run a new completion decision or require a new outcome document. Its original completion date is retained when supplied, and its original completer remains unknown. A completion before the source creation date produces a review warning: this can happen when exporting previously imported historical work. The new task's creation date records this import; the source creation date remains in its import history. A historical import does not award fresh Points or XP, send assignment notifications, or trigger creation automations. Imported work gets a new destination identifier. Comments, attachments, memberships, original authors, external links, Focus groups, milestones, document links and activity history are not migrated by this CSV flow.

No provider credentials are needed and no source system is contacted or modified. The upload itself is discarded after parsing. The tenant database retains the bounded parsed row values, mappings, source identifiers, file hash, importing member, timestamps, errors and resulting task links as the import ledger. These records are subject to the workspace's normal database retention and backup policy; cancelling a run does not erase its history.

## Invite one person or a group

In **Admin → Team**, use **Invite your team**.

1. Paste up to fifty distinct email addresses, separated by new lines, commas, semicolons, or spaces.
2. Choose **Role for everyone**. Use **Member** for ordinary participation; **Admin** gives everyone newly invited workspace administration access.
3. Choose **Send invitations** and inspect the per-address results.

The results distinguish queued invitations, existing members, pending invitations, and entries needing retry. Repeated addresses are counted once. Retrying a list skips existing members and usable pending invitations, preserving their roles and links. It does not resend every invitation in the list.

Recipients open their invitation and use one of the workspace’s enabled sign-in methods. With email/password they choose a name and password; with a provider they use the invited address. An expired, revoked, or already used link cannot be accepted.

## Manage pending invitations

The **Invitations** list shows the invited address, role, and expiry. Use **Resend** when a recipient needs a replacement invitation, and **Revoke** when the invitation should no longer grant access. Explicit resending is separate from retrying failed entries in a bulk invitation.

If delivery is uncertain, inspect the recorded result before sending again. A queued message is not evidence that the recipient has received or accepted it. Check the member list to confirm that access was established.

## Change member roles and access

Use the member row’s **Role** and **Status** selectors. Roles are **Member** and **Admin**; statuses are **Active** and **Suspended**. The workspace must retain at least one active admin, so the last active administrator cannot be demoted or suspended.

Suspension removes the member’s current browser sessions and revokes MCP authorizations. It also stops their active assistant work as applicable. Setting the member back to Active permits them to sign in again; revoked agent connections need fresh authorization.

Workspace membership does not replace project, team, or room access rules. Check the relevant scope when a member cannot open a work item. Private retrospective and refinement rooms require explicit participation, including for administrators. Review drafts remain author-private; edition access is granted separately.

## Choose how the workspace estimates work

Under **Admin → Settings → Work estimation**, choose **T-shirt sizing** (XS, S, M, L, XL) or **Story points** (0, 1, 2, 3, 5, 8, 13, 21), then **Save estimation method**. Only active admins can change it. Work-item estimate fields and refinement voting follow this choice; numeric estimates display with **SP**.

Existing estimates keep their original values. A refinement already in progress needs a new round after a change. Previous votes remain in their original scale, unrevealed votes stay private, and applied outcomes remain unchanged. Review and save any pending changes again before applying them.

## Review shared configuration

**Allow members to create Apps** starts disabled. Admins can always create Apps; enabling the setting lets other active members create their own. Disabling it later prevents new member-created Apps without revoking existing credentials. Owners manage and revoke their Apps in **Account settings → Apps**. See [Apps and API setup](https://tellenze.com/help/apps) for grants, attribution and integration examples.

Under **Admin → Settings → Gamification**, choose whether the workspace awards points and XP, then **Save gamification setting**. Gamification starts enabled. Disabling pauses new task, onboarding and milestone rewards and new Rhythm streak credit, and hides progression displays and celebrations while keeping work, onboarding and personal planning available. Existing reward history is preserved. Enabling resumes future rewards; it does not backfill work completed while disabled. Reopening previously rewarded work still reverses its original award so balances remain accurate.

Use **Workflows**, **Templates**, and **Automations** for reusable processes, **Integrations** to browse available and planned tools or manage the GitLab connection, and **Agent reactions** for workspace/provider policy. Their dedicated guides explain the consequences of changes. **Insights** provides delivery reporting when enabled; figures should be read with their selected filters and data availability.

## Choose workspace sign-in methods

Open **Admin → Integrations → Sign-in methods** to configure email/password, Google, Microsoft, or an eligible Emergent Accounts integration. A method becomes available on this workspace’s sign-in page after you save a complete enabled configuration. Keep at least one method enabled. Disabling a method ends access through sessions using it, so confirm another usable method before changing policy.

Google and Microsoft need an application registered with the provider. Use the exact callback URL shown in the card; Microsoft also requires your directory tenant ID. Secrets remain private after saving. Emergent Accounts is available only to workspaces explicitly entitled by the platform operator, and its configuration stays within that workspace.

Email/password members can use **Forgot password** to set or reset their password. Recovery works only for an existing active membership while the method is enabled. It does not create a new member or change their role.

Platform administration is separate from workspace administration. A Tellenze operator can inspect the workspace directory and suspend or resume a workspace, but being a workspace admin does not grant operator access.

