Skip to main content

No product access needed

Scope workspace access and approvals

Use an audience, workspace, scope set, expiration, and revocation path to make a private grant explainable before it is issued.

Expected outcome

You can review access as a bounded grant instead of treating an API key or connected client as an all-purpose credential

You can use this public guide without a Tempera account, product credential, or private workspace. Product access begins only after private onboarding.

Before you start

  • A named person, service, or client and the job it must perform
  • The intended organization, project, and environment

Steps

  1. 01

    Name the audience

    Identify which private surface the grant is for, such as workflows, connectors, MCP, or model access, before selecting a scope

  2. 02

    Bind it to one workspace

    Confirm the organization, project, and environment in human terms. A useful grant cannot silently drift into another workspace

  3. 03

    Choose the smallest scope set

    Grant only the read, write, invoke, or run capability needed for the named job. Keep administrator access separate

  4. 04

    Set expiry and recovery

    Give the grant an expiration, owner, and revocation path so a lost client or changed job can fail closed without disturbing unrelated access

What success looks like

  • The owner can explain every audience and scope in the requested grant
  • The grant has an explicit workspace, expiration, and recovery path
  • No public page created a key, OAuth grant, or authenticated session

If something is blocked

  • If a routine task appears to need administrator access, clarify the job and select a product-specific scope instead
  • If the intended workspace is unclear, stop before issuing or requesting access and resolve that identity boundary first