PromptPress is workspace-scoped. Content, workflows, prompts, billing, and settings are controlled within the active workspace boundary.
Workspace Types
Common operating model:
- Personal workspace: individual work and lightweight experimentation.
- Team workspace: shared editorial and operational workflows with role controls.
Use team workspaces for production publishing.
Role Strategy
Use least privilege by default.
| Role | Recommended Responsibility |
|---|---|
| Owner | Billing control, account-critical actions, membership governance |
| Admin | Workflow operations, content governance, team operations |
| Member | Day-to-day drafting, editing, and approved publishing tasks |
Some installations may expose additional custom roles, but owner/admin/member remains the core operational model.
Access-Sensitive Areas
Treat these as controlled surfaces:
- Billing and subscription changes.
- Membership and role management.
- Prompt and model governance.
- High-impact publishing operations.
These should be limited to designated owners/admins.
Membership Lifecycle
Invite and Onboard
- Invite user to the correct workspace.
- User accepts invite and completes identity setup.
- Assign role based on least privilege.
- Validate access to required modules only.
Step-by-Step: Onboard a New Editor
- Invite the user to the correct team workspace.
- Assign
memberrole first. - Ask the user to log in and confirm basic module access.
- Confirm they can draft content but cannot change billing or membership.
- Promote to
adminonly if operational responsibilities require it.
Step-by-Step: Offboard a Team Member Safely
- Confirm ownership of any active workflows/campaign tasks.
- Transfer responsibilities where needed.
- Remove workspace membership.
- Remove pending invites for duplicate accounts if present.
- Verify no unexpected access remains.
Ongoing Access Management
- Review memberships monthly.
- Remove stale invites.
- Remove access quickly when responsibilities change.
- Keep ownership handoff documented.
Operational Governance Checklist
- Owner count remains low.
- Admin privileges are intentional and reviewed.
- Sandbox and production workspaces are separate.
- Team naming and workspace structure are audit-friendly.
Access Incident Playbook
If a user reports access issues:
- Confirm workspace slug and active session context.
- Confirm membership and role.
- Confirm invitation/identity completion state.
- Retest affected route under same role.
- Escalate with account ID, route, and UTC timestamp.