Expected outcome
You can review access as a bounded grant instead of treating an API key or connected client as an all-purpose credential
You can use this public guide without a Tempera account, product credential, or private workspace. Product access begins only after private onboarding.
Before you start
- A named person, service, or client and the job it must perform
- The intended organization, project, and environment
Steps
- 01
Name the audience
Identify which private surface the grant is for, such as workflows, connectors, MCP, or model access, before selecting a scope
- 02
Bind it to one workspace
Confirm the organization, project, and environment in human terms. A useful grant cannot silently drift into another workspace
- 03
Choose the smallest scope set
Grant only the read, write, invoke, or run capability needed for the named job. Keep administrator access separate
- 04
Set expiry and recovery
Give the grant an expiration, owner, and revocation path so a lost client or changed job can fail closed without disturbing unrelated access
What success looks like
- The owner can explain every audience and scope in the requested grant
- The grant has an explicit workspace, expiration, and recovery path
- No public page created a key, OAuth grant, or authenticated session
If something is blocked
- If a routine task appears to need administrator access, clarify the job and select a product-specific scope instead
- If the intended workspace is unclear, stop before issuing or requesting access and resolve that identity boundary first