Your team and workspace

07Documentation

Your team and workspace

Seats, permissions, and exactly what the AI can see.

Sign in and set up your account

Get from the sign-in screen to a working workspace, then lock the account down behind you.

How-to6 min read

Vernais shows a sign-in screen before anything else. Once you sign in, you clear a check or two, then pick a workspace. Only then does the app open. This page walks that path, then covers the account settings you will want later.

Create your account

Tip

Sign up with your work email — the shared invite code checks your email domain before it lets you in.

  1. 1
    Open the sign-in screen

    It is the first thing Vernais shows. Select Create an account.

  2. 2
    Enter your email and a password

    Your name is optional. Type the password twice — the second field is Confirm password. It needs 8 characters or more, and Vernais refuses one that is too common.

  3. 3
    Or select Continue with Google

    The Google button appears only when your deployment has Google sign-in configured. You go to Google and come back signed in.

  4. 4
    Clear whatever your account needs next

    A work-email account lands on a verification screen — open the link Vernais emails you, or select Resend verification email. An account with no plan yet picks one. Then you reach workspace setup, because a new account has no workspace.

Note

Google links itself to an existing password account on the same address only when that address is verified. If it is not, you see Sign in with your password to link Google to your account. Sign in with the password once. Google works after that.

Reset a password you forgot

Tip

A reset signs out every device you own — treat it as a full account reset, not a small repair.

  1. 1
    Select Forgot password?

    It sits under the password field. Enter your email and select Send reset link.

  2. 2
    Read the reply carefully

    It always says If that email is registered, a reset link has been sent. Vernais never tells anyone whether an account exists, so nobody can fish for your address.

  3. 3
    Open the link and pick a new password

    The link works once, then expires.

  4. 4
    Sign in again

    Setting the new password signs out every device, including the one you are on.

Create a workspace, or join your team's

A workspace is a sealed box. It holds one team's data, chats and knowledge graph in its own two private databases. Nothing inside one workspace is visible from another.

Tip

If your team already runs Vernais, join theirs — a workspace you create starts empty and inherits nothing from the one they built.

Create

You name it and you own it. Vernais builds it blank: no chats, no data, no graph. You connect your tools and build the graph inside it. Your row is tagged created.

Join with code

You paste the invite code a teammate sends you. You land in their workspace with everything already there. Your row is tagged joined.

  1. 1
    Pick New workspace or Join with code

    The two cards sit at the top of the setup screen. When your account cannot create one, the cards are hidden and the join form is all you see.

  2. 2
    Name it, or paste the code

    A new workspace also lets you pick a pixel logo. Both paths let you pick your avatar.

  3. 3
    Select Create workspace or Join workspace

    You land inside it right away.

A workspace you create is genuinely empty. That is the design, not a fault. Next you connect a tool and build the graph inside it.

But

Create your own when you want a slice nobody else touches — a side product, a trial run, one client. The test: if a teammate could already ask Vernais why are checkouts dropping and get an answer, join them instead of starting over.

The limit
The invite code only admits the owner's company email domain
What it means
An owner, or anyone who can manage invitations, turns on Super invite to lift the domain lock
Do this instead
Ask them to send you an email invitation instead — see manage your team
The limit
A domain-locked code also needs a verified email address
What it means
Verifying happens on the screen Vernais shows a work-email account right after sign-in
Do this instead
A Super invite code skips both checks, and an email invitation skips them too
The limit
The owner signed up on a free provider like gmail
What it means
There is no company domain to match, so the code admits nobody
Do this instead
That workspace takes people by email invitation only
The limit
You can only join, never create
What it means
Your account belongs to a verified company, or your plan has no room for another workspace
Do this instead
Join your company's workspace with its code — permissions and seats covers the plan side

Fill in your profile

Go to Settings, then Profile. The four fields below show to everyone in your workspace.

  • Avatar — a cartoon character. It shows on the sidebar, the member list, and everything you create.
  • Display name — up to 80 characters.
  • Role / title — up to 120 characters. It sits on your profile card for everyone in the workspace.
  • About you — up to 300 characters, on the same card.
Note

Role / title is free text on a card. It grants nothing. What you can actually do is a per-person permission set the workspace owner assigns — see permissions and seats.

Change your email or password

Tip

A password change signs out every other device — that is what makes it the right move the moment you suspect trouble.

Change your password

Settings → Login & security → Change password. Enter your current password, then the new one twice, then select Update password. Every other device is signed out. This device stays in.

Change your email address

Settings → Profile → Email address → Change email. Type the new address and your current password, then select Send confirmation link. The link goes to the new address, and the change only lands when you open it. The reply is deliberately neutral: If that address is available, a confirmation link has been sent.

Add a password to a Google account

A Google-only account has no password to change. Login & security offers Send password setup link instead. Adding a password does not disconnect Google — you can then use either one.

Check which devices are signed in

Tip

Read this list the day you lose a laptop — revoking a session cuts that device off at once.

Settings → Login & security → Active sessions lists every browser signed in to your account, your own device first.

What you seeWhat it tells you
The labelThe browser and device, worked out from the browser itself — Chrome on Mac, Safari on iPhone.
The IP addressWhere that session signed in from.
signed in and a dateWhen the session started.
This deviceThe tag on the session you are reading this from.
  • Revoke one — select the icon at the end of its row. That device is signed out at once.
  • Sign out everywhere else — select Sign out of all other devices. It appears only when there is another one. This device stays in.
  • Sign out here — the Sign out item at the bottom of the settings rail. Your other devices stay signed in.

Leave a workspace, or delete your account

Three buttons sound alike and destroy very different things. Read the row before you pick one.

ActionWhereWhat it destroys
Leave a workspaceSettings → Workspace → General → Danger zoneNo data. You lose access until someone invites you back, and you land in another workspace you belong to, or on the setup screen.
Delete a workspaceThe same danger zone, owner onlyBoth of that workspace's databases and all of its data, for everyone in it. Your account and your other workspaces are untouched. If the delete cannot finish, Vernais aborts it and leaves the workspace whole so you can retry.
Delete your accountSettings → Profile → Delete accountYour account, plus every workspace you own and all of its data, for everyone in it. Memberships in workspaces other people own are removed.
Note

An owner cannot leave the workspace they created — the danger zone offers Delete workspace instead. Ownership cannot be handed to anyone else, so who creates the workspace is a lasting decision.

Careful

Deleting your account cannot be undone. It also deletes every workspace you own, with all of its data, for everyone else in them. You confirm with your password and by typing DELETE. A Google-only account confirms with its session, because it has no password.

Invite and manage your team

Send an invite, pick the seat it carries, then tune what that one person can do.

How-to6 min read

Two things decide what a teammate can do. Their seat sets the AI ceiling. Their permissions set everything else. You choose the seat when you invite them. You tune permissions after they join. There are no roles to pick — see Permissions and seats for the full model.

Pick the seat before you invite

Tip

Choose the seat with one question: does this person need to ask the AI anything?

SeatWhat it unlocksWho it fits
Max seatEverything a Power seat gets, plus AI chat, the agent and root-cause investigationsA PM who asks questions and runs investigations
Power seatData, dashboards and the knowledge-graph browser. No AI chat, no agent, no investigations.Someone who reads what others found

The seat is a hard ceiling. Vernais takes the permission set you assigned and strips the three AI capabilities out of it unless the person is on a Max seat: chat.use, investigation.run and codebase.analyze. In the permission editor those three toggles sit greyed out on a Power seat, tagged ⚡ Max seat. No other grant buys AI back.

Note

Only the workspace owner can change a seat. If you hand someone team management, they can edit other people's permissions — the seat stays with you.

Invite someone by email

  1. 1
    Open the invite panel

    Go to Team, then select Invite member. Email, the shared code and Super invite all live in this one panel.

  2. 2
    Enter their address

    Type it into Email address. The invitation works for that exact address and no other.

  3. 3
    Choose the seat

    Pick Max seat or Power seat in the Seat field. It is the only choice the invitation carries, and it defaults to Max.

  4. 4
    Send it

    Select Send invite. They appear under Pending invitations until they accept.

The invitation is single-use and locked to that address. When they accept, they join with the seat you chose plus the default rights described below. To pull an invite back before it is used, select Revoke on its row — the link stops working at once.

The limit
A Starter plan includes one seat
What it means
Seats are counted against the workspace owner's plan, not per workspace
Do this instead
Ask the owner to upgrade to Growth or higher — the invite panel is replaced by an upgrade note until then
The limit
The plan's seats are full
What it means
A seat frees up when someone is removed
Do this instead
Remove a member who no longer needs access, or upgrade the plan
The limit
An email invitation expires after 7 days
What it means
It also dies the moment it is used or revoked
Do this instead
Send a fresh invite from the same panel
The limit
Someone who is already a member can't be re-invited
What it means
Vernais refuses it as a duplicate
Do this instead
Change their seat or permissions on the roster instead

Share one invite code instead

Tip

Reach for the code when several people join at once and they all need the same seat.

  1. 1
    Set the joiner seat

    Team → Invite memberShare an invite link. Set New members join with this seat, then select Save.

  2. 2
    Copy the code

    Select Copy. Anyone who enters that code joins with the seat you saved.

  3. 3
    Read the line underneath

    It states exactly who the code admits right now, so you don't have to guess.

By default the code only admits people whose email domain matches the owner's company domain, and their email has to be verified. If the owner signed up with a free provider like Gmail, there is no company domain — the code then admits nobody, and email invites are the only way in.

To let a contractor or anyone outside your company use the code, turn on Super invite. The code then accepts any email address. If the code leaks, select Regenerate: the old code stops working for anyone who has not joined yet, and people already in are untouched.

But

Email invites are better when seats differ per person, or when you want a record of who invited whom. The test: if you would give two people different seats, the shared code is the wrong tool.

Change what one person can do

Tip

Permissions are per person, edited from their row — there is no role to change and no matrix to maintain.

  1. 1
    Open their permission set

    Team → Members. Select the permissions link on their row — it reads N permissions · Manage, or Full access for the owner.

  2. 2
    Toggle capabilities

    Each capability is a checkbox, grouped by section: AI Chat, Products, Initiatives, Data, Team, Integrations, Storage, Billing and more. Use Enable all or Disable all to move a whole section.

  3. 3
    Read the tags

    A default tag marks an ordinary right that is on the day someone joins. A ⚡ Max seat tag marks an AI capability, greyed out on a Power seat. An always on tag marks a right nobody can revoke.

  4. 4
    Save

    Select Save permissions. The change applies to their next request.

Capabilities come in three kinds, and knowing which is which explains most surprises.

  • Ordinary rights — viewing the dashboard, data, initiatives, pages, the calendar. On the moment someone joins.
  • AI rights — chat, investigations, codebase analysis. On by default too, but they survive only on a Max seat.
  • Manage rights — connecting a tool, running the brain, editing any initiative, managing the team, workspace settings, billing. Off until you turn them on for that person.
Note

Turning a capability off hides that section from them. It does not grey out a dead button — their sidebar is shorter. That is why a teammate reporting "I can't see Chat" is usually a seat problem, not a permission one.

Note

One toggle is locked on for everyone: personal settings. That is how a person reaches their own profile and signs out, so tightening permissions can never trap someone with no way out.

You cannot edit the owner's permissions — the person who created the workspace always holds every one of them. A teammate you granted team management can edit other people but never themselves, and can only hand out permissions they already hold. Nobody can promote themselves that way.

Remove someone

  1. 1
    Find them

    Team → Members. Search by name or email if the roster is long.

  2. 2
    Remove

    Select the trash icon on their row and confirm.

  3. 3
    Check what happened

    They lose access on their next request and need a fresh invite to come back. Their seat frees up for someone else.

Note

Only the workspace owner can remove a member, and the owner can't be removed. There is no ownership transfer, so whoever creates a workspace keeps it — pick that person deliberately.

Permissions and seats

Two dials decide what a person can do in Vernais: their seat, then their permissions. The seat is checked first, and it can veto everything else.

Reference6 min read

Vernais has no roles. There is no admin, no manager, no viewer. The workspace owner hands each person their own list of capabilities, one by one. On top of that sits a seat, which is a billing ceiling.

Read the two dials in this order. The seat says whether a person can touch the AI at all. The permissions say which sections and actions they get. An AI permission that the seat forbids does nothing.

Seats: the AI ceiling

Tip

A Power seat has no AI. No permission can give it back.

Every member holds one of two seats. This is the hard billing line, so only the workspace owner can move someone between them. A person whose seat has never been set counts as Max.

SeatWhat it unlocksWhat it never gets
Max seatAI chat, the agent, web and research, root-cause investigations, codebase analysis, plus all their data accessNothing — the ceiling is open
Power seatData, the knowledge graph, dashboards, initiatives, reports, pages, live chat, calendarAI chat, investigations, codebase analysis — permanently

The mechanism is short. Vernais takes the person's assigned permissions, then deletes the AI ones unless the seat is Max. In the code the seats are stored as chat (Max) and power.

You can see this in the permission editor. Every AI capability carries a ⚡ Max seat tag. On a Power seat those three checkboxes are also greyed out, so you cannot tick them at all. If they were ticked before the seat changed, they stay stored and stop working.

Note

A Power seat also loses the Chat & AI pane in Settings. Panes are hidden, not greyed out, so the person will not see an option they cannot use.

Permissions: assigned per person

Tip

The owner ticks boxes for one human being at a time. There is no role to copy.

Open the Team section, find the person's row, then click the permissions link on it — it reads N permissions · Manage. A modal lists all 37 capabilities, grouped by section. Tick what that person needs and save. The list you save becomes their whole permission set.

Each section is gated by one right. Switch that right off and the section vanishes from their sidebar — no error message, no greyed-out button. The other rights inside a section hide an action rather than the section: turning off Create initiatives leaves Initiatives visible and takes the button away.

The three tiers

Each capability carries a tier. The tier tells you what the capability is, not who gets it.

Baseline (20)

Ordinary view and use rights. On for a brand-new member. The owner can switch any of them off for one person.

AI (3)

AI chat, root-cause investigations, and codebase analysis. Seat-gated: they work on a Max seat and never on a Power seat.

Elevated (14)

The manage and admin powers — edit products, connect tools, run the brain, manage the team, workspace settings, billing. Off by default. The owner grants them per person.

A new teammate you have not configured starts with baseline plus AI — 23 capabilities. On a Max seat they can chat on day one. On a Power seat the ceiling strips the AI three, leaving the 20 baseline rights.

Their real access is the set the owner assigned, minus the AI rights their seat forbids.

The permission catalog

These are the 37 capabilities, grouped by section in the order the editor shows them.

CapabilitySectionTier
AI chat / agent / web / researchAI ChatAI
Run root-cause investigationsAI ChatAI
View the dashboardDashboardBaseline
Your own task queueMy TasksBaseline
Your own inboxInboxBaseline
View product detailsProductsBaseline
Edit products + New productProductsElevated
View initiativesInitiativesBaseline
Create initiativesInitiativesBaseline
Edit initiatives you own/reportInitiativesBaseline
Update your assigned task statusInitiativesBaseline
Edit ANY initiative (override)InitiativesElevated
Take Measure actions on any initiativeInitiativesElevated
View launch trackingLaunchesBaseline
Take a reading on any launchLaunchesElevated
Use live chat (public + own private)Live ChatBaseline
Create / delete channelsLive ChatElevated
Create / view / edit pages per permissionPagesBaseline
Use the calendarCalendarBaseline
Browse the KG data / graphDataBaseline
Add a new nodeDataElevated
View reportsReportsBaseline
Update any reportReportsElevated
See the member listTeamBaseline
Invite / remove / seat / permissionsTeamElevated
See public workspace activityActivityBaseline
Connect / sync / disconnect / purgeIntegrationsElevated
Run Corvex manuallyIntegrationsElevated
Analyze approved or user-provided codebasesCodebaseAI
Choose the GitHub repo for technical task analysisCodebaseElevated
See all members' files + who uploadedStorageElevated
See your own upload usageStorageBaseline
See your own seatBillingBaseline
Manage plan / paymentBillingElevated
Workspace settings / members / invitesSettingsElevated
Your own personal settingsSettingsBaseline · always on
Help & docsHelpBaseline
Note

Your own personal settings can never be switched off, by anyone. It is how a person reaches their profile and signs out. Tightening permissions can never trap a teammate with no way out.

One pairing is worth knowing. Any initiative capability quietly adds View initiatives when you save, because you cannot act on what you cannot see.

What the owner can always do

The owner is the person who created the workspace. That is permanent — there is no way to hand ownership to someone else.

  • Hold every permission. All 37, always. The owner cannot be locked out.
  • Stay uneditable. Nobody can change the owner's own permissions, including the owner.
  • Change any seat. Moving a person between Max and Power is owner-only, because the seat is the billing ceiling.
  • Grant anything. The owner is not bounded by their own set the way a delegate is.
  • Delete the workspace. An owner cannot leave a workspace. Deleting it is the only exit.
But

You can delegate the roster. Grant Invite / remove / seat / permissions and that person can invite, remove and set permissions for everyone else. Three limits still hold. They cannot edit their own permissions. They cannot grant a right they do not hold themselves. And despite the word seat in that label, they cannot change a seat — that stays with the owner.

Limits

The limit
A Power seat can never use AI chat, investigations, or codebase analysis
What it means
The ceiling holds for as long as the seat does. Moving the person to a Max seat lifts it
Do this instead
Ask the owner to change it in Team → the person's row → the Seat dropdown
The limit
A delegate can only grant permissions they hold themselves
What it means
The check runs on every save, against their own effective set
Do this instead
Have the owner grant them that permission first, or have the owner make the change directly
The limit
The owner's permission set cannot be edited
What it means
Fixed for the life of the workspace; ownership does not transfer
Do this instead
Grant a trusted teammate Invite / remove / seat / permissions and the elevated rights they need
The limit
Nobody can switch off a person's own personal settings
What it means
Locked on in the editor and forced on at save
Do this instead
To cut someone's access, remove them from the workspace instead

When someone cannot see a section

Sections are hidden rather than disabled, so there is no error message to read. Check in this order — it is the same order the code checks.

  • Seat first. If the whole Chat section is missing, look at their seat. A Power seat strips AI chat, investigations and codebase analysis together, and no permission will fix it.
  • Permission second. Open their row in Team and click Manage. A section disappears when its gate right is off — View initiatives for Initiatives, Browse the KG data / graph for Data, View reports for Reports.
  • Then the pane. Settings panes follow the same rule. Members & permissions and Invitations need team management, General and Workflows need workspace settings, Codebase needs the repo-choosing right, and Chat & AI needs AI chat.
AI chat is ticked for this person, so why can't they use it?
Check their seat. On a Power seat the ticked AI rights are stored but stripped when Vernais evaluates access, so they do nothing. Move the person to a Max seat from the Seat dropdown on their row in Team.
Can I give someone the same access as a teammate?
Not by copying a role — there are none. Open both rows in the permission editor and match the ticks. Each section has an Enable all shortcut.
Can I transfer the workspace to someone else?
No. The creator is the owner permanently. The closest option is granting them the elevated permissions they need, including team management.

What the AI can see

A workspace is a wall. Here is exactly what sits on each side of it, and why your new one opened empty.

Explanation6 min read

One constraint shapes most of what follows: when Vernais answers from your connected data, every claim has to trace back to a record it can point at. It will not invent a cause. A question it cannot ground in your data returns nothing rather than a guess. Questions about the outside world, or about general knowledge, it answers like any good assistant — and tells you which world the answer came from.

So "what can the AI see?" has an exact answer. It sees the records in the workspace you are in right now. Not your account. Not the workspace you were in this morning. This page maps that line.

What a workspace actually is

Tip

A workspace is two private databases, and Vernais builds them empty.

When you create a workspace, Vernais creates two databases named after it. One holds your working data: chats, initiatives, files, activity. The other holds the knowledge graph. It copies the shape of the global setup — the table names and the columns — and copies none of the contents.

That matters more than it sounds. A second workspace is not a view, a filter, or a folder. It is a separate store. Data cannot leak across it, because a query run in one workspace never names the other database at all.

Careful

Deleting a workspace drops both of its databases. The chats, the graph, the initiatives and the activity go with it, for everyone in it, with no undo. Only the workspace owner can do it.

What stays inside one workspace

Tip

If your team's work produced it, it stops at the workspace line.

WhatWhat that means
Knowledge graphEvery record the AI learned from, and the entities and topics built on top. Corvex writes into the workspace you ran it in, and nowhere else.
ChatsThreads and messages live in that workspace's database.
MemoryWhat the AI picks up about your work is written to the active workspace. It does not ride along with your account.
InitiativesThe problems you are working, with their hypotheses, evidence and tasks.
Activity logWho did what. Each workspace keeps its own feed.
FilesUploads and folders in Storage.
Tool connectionsThe credentials, and whether a tool reads as connected. Most people expect this one to be shared. It is not.

Memory deserves a second look, because it surprises people who use two workspaces. Tell the AI something useful in one workspace and it writes that to that workspace's database. Ask about it from another workspace and it has no idea. The write refuses to run at all if no workspace is active, rather than fall back to a shared store. See What it knows about you.

You connect each tool again in every workspace

Tip

A connection belongs to a workspace, not to your account.

This is the one that catches people, because the tool list looks shared. The catalog is global: every workspace shows the same set of supported tools, with the same logos. The connection is not. Each connection record carries the id of the workspace that made it, and every screen filters to your workspace before it draws a single card.

So a tool you connected last week in one workspace reads as not connected in the next one. The credentials do not travel, and the records they pulled do not travel either. A second workspace means connecting the tools again, syncing them, and running Corvex there. See Connect a tool and Build the graph.

But

Splitting into separate workspaces is not always right. Each one is another set of tools to connect, another sync, and another Brain run — and no single question can ever reach across two of them. The test: if you would ever want one investigation to read both sets of data, they belong in one workspace.

Switching workspaces changes every answer

Tip

Check which workspace you are in before you trust a number.

Switching re-points the whole app. Every section drops what it was holding and re-fetches from the new workspace's databases. The AI does the same. An investigation, a data lookup, or a chat question runs against the workspace that is active when you press send.

The honest consequence: the same question can give two different answers in two workspaces, and both are correct. One workspace has Stripe and Sentry synced. The other has nothing yet. The second one says it has no evidence, which is the right answer for the data in front of it. See When it finds no evidence.

What the line does not cover

Three things sit outside the workspace, and knowing which is which saves a lot of confusion.

  • Your account — your name, avatar, password and signed-in devices belong to you, across every workspace you are in.
  • The tool catalog — the list of supported tools is the same everywhere. Only the connections are scoped.
  • General knowledge and the web — a workspace walls off your data, not the AI's ability to think. It will still explain a concept or search the web, and it tells you the answer came from there and not from your records.
The limit
A question can only reach one workspace's data.
What it means
The workspace that is active when you send it.
Do this instead
Switch workspaces and ask again, or keep tools that belong together in one workspace.
The limit
Signed in with no workspace, every data screen refuses to load.
What it means
Clears the moment you create or join one.
Do this instead
Create a workspace, or ask a teammate for an invite.
The limit
Running Corvex needs a permission that is off by default.
What it means
The workspace owner turns it on per person.
Do this instead
Ask the owner for it, or ask someone who already has it to run the Brain for this workspace.

Common questions

Why is my new workspace empty?
Because Vernais built it empty on purpose. It copies the shape of the databases and none of the contents, so nothing from your other workspaces can appear in it. Connect your tools here, sync them, then run Corvex from Integrations to fill the graph.
Why does it say a tool is connected when I never connected it here?
Someone else on your team connected it in this workspace. Connections belong to the workspace, not to the person who made them, so a teammate's work shows up as connected for everyone in it. If you expected it to be connected because you set it up in a different workspace, that is not how it works — connect it again here.
I switched workspaces and the AI forgot what I told it. Is that a bug?
No, that is the wall doing its job. Memory is written into the workspace that was active at the time, so it does not follow you across. Tell it again in this workspace, or move the work into one shared workspace.
Can I ask one question that spans two of my workspaces?
No. An investigation reads one workspace's knowledge graph, and there is no way to join two. If two sets of data need to be compared, connect both sets of tools inside a single workspace and run Corvex there.

See who did what

The Activity log answers one question: who did what in this workspace, and when. Every entry is timestamped, and no code path edits or deletes one.

How-to4 min read

What the activity log is

Vernais writes an entry each time someone changes the workspace. Creating an initiative. Connecting a tool. Running the Brain. Each entry holds the actor, the action, the time, and the thing it touched. The log is append-only. The code inserts entries and nothing else — there is no update path, no delete path, and no button that edits one. What you read is what happened.

Tip

The log records that an action happened, not the content it produced.

What gets logged

TypeWhat triggers an entryWho can see it
InitiativesCreate or delete one, reassign the owner, lock a metric, anchor a hypothesis, pick a solution, attach a fileEveryone
Act tasksStart Act, create or move a task, file a bug, merge a branch, scan SentryYou only
ProductsCreate or delete a productEveryone
PagesCreate, edit or delete a page or folderEveryone for public pages. You only for the rest.
InvestigationsStart an investigationYou only
IntegrationsConnect, sync, disconnect, purge, change settings or a webhookOwner and team managers
DataRun Corvex pipelineOwner and team managers
Web scrapesStart a scrapeOwner and team managers
WorkspaceCreate, join, rename, leave, regenerate the invite codeOwner and team managers
TeamChange a role or seat, edit permissions, invite or remove a memberOwner and team managers
StorageUpload a file, create or delete a folderYou only
Live chatCreate or delete a channelYou only
AccountSign in or out, change your password or emailYou only, always

Chat writes no entry at all. Asking the AI a question logs nothing, and no message text is stored here. Elsewhere the entry names the thing, not the work inside it. A page entry names the page, never its body. An integration entry names the tool, never the records it pulled. Two entries do carry your words. An investigation stores its question, and a scrape stores its query. Both sit in the detail line, capped at 600 characters.

Who sees what

Everyone

Shared work on shared objects — initiatives, products, reports, public pages. Any member with the Activity permission reads these. That permission is baseline, so every role has it.

You only

The default. An action lands here unless the code marks it shared or management. Your logins, uploads and investigations are yours alone. Account entries stay private even from the owner.

Owner and team managers

The control plane — workspace, team, integrations, Brain runs, scrapes, codebase. A platform admin, the workspace owner, or anyone with Manage team reads these.

Attendees only

A meeting transcript entry reaches the people on that invite and nobody else. It stays out of everyone else's counts too.

Tip

Visibility follows the action, not the type — an Act task is typed Initiatives but stays private to you.

Find an event

  1. 1
    Search by person, action or target

    The box matches the entry title, the detail line, the actor's name and the target label. It waits 280ms after you stop typing, then runs. It does not match the action id or the meta chips.

  2. 2
    Narrow by type

    The dropdown beside the search box lists only the types your workspace has, each with its own count.

  3. 3
    Read the day and time

    The When column carries a day label — Today, Yesterday, a weekday, then a date — next to a relative time. Hover it for the full timestamp.

  4. 4
    Open the row

    Click any row. A drawer shows the actor, action, detail, type, target id and the exact time. Meta values land here too, like a scrape's page count and intensity.

  5. 5
    Load more

    The feed starts at 40 events and appends 40 at a time.

But

Reach for the type filter when you are surveying — 'what changed in integrations this week'. It gives you a clean, countable slice, and it runs in the database rather than over the rows on screen. The counter-case: when you know a name or a phrase, search lands on the row in one step. A type guess can send you to the wrong slice. Report events, for instance, sit under Other. Test: can you name the type without thinking? Filter. If not, search.

The three numbers at the top

Events

Every event in this workspace you are allowed to see, across all pages. The type filter and the search do not change it.

People

Distinct actors among the rows loaded right now — not across the whole log. Load more raises it.

Last activity

How long ago the newest loaded event happened.

Where the log stops

The limit
The feed reads the newest 20,000 matching events
What it means
Paging works inside that window. Older events are not reachable by clicking Load more.
Do this instead
Filter by type or search first. Both run in the database before the window is cut, so a narrow query reaches much further back.
The limit
One page returns at most 500 events
What it means
The screen asks for 40, and appends 40 per click.
Do this instead
Ask an admin for a bigger page if you are auditing in bulk.
The limit
Export log does not export
What it means
The button reloads the feed. Nothing downloads.
Do this instead
Copy what you need from the row drawer.
The limit
Report and codebase events have no filter option
What it means
They fall under the Other type, and the dropdown does not offer them.
Do this instead
Search the report or repo name, or page through All activity.
The limit
A failed write is dropped, not retried
What it means
Each entry is inserted on a background thread, so logging never slows your action down. If the database rejects the insert, your action still succeeds and the entry never appears.
Do this instead
Treat the log as a strong record of work, not as a compliance guarantee.
Does switching workspace switch the log?
Yes. Each entry is written into the active workspace's own database, and the feed reads that same database. A workspace shows only its own events. There is no combined view across workspaces.
Can anyone edit or delete an entry?
No. The code only inserts. No path updates or removes an event, and no screen offers it.
Why can't I see my teammate's sign-ins?
Account events are private to the person who did them. That holds for the workspace owner too.
Why did the feed drop back to 40 rows?
It refreshes itself every 30 seconds while the tab is visible, and a refresh reloads the first page. Click Load more again after it runs.
Can I turn the log off?
An admin can switch recording off for the whole deployment. Entries already written stay, and stay readable.