07Documentation
Your team and workspace
Seats, permissions, and exactly what the AI can see.
Sign in and set up your account
Get from the sign-in screen to a working workspace, then lock the account down behind you.
Vernais shows a sign-in screen before anything else. Once you sign in, you clear a check or two, then pick a workspace. Only then does the app open. This page walks that path, then covers the account settings you will want later.
Create your account
Sign up with your work email — the shared invite code checks your email domain before it lets you in.
- 1Open the sign-in screen
It is the first thing Vernais shows. Select
Create an account. - 2Enter your email and a password
Your name is optional. Type the password twice — the second field is
Confirm password. It needs 8 characters or more, and Vernais refuses one that is too common. - 3Or select
Continue with GoogleThe Google button appears only when your deployment has Google sign-in configured. You go to Google and come back signed in.
- 4Clear whatever your account needs next
A work-email account lands on a verification screen — open the link Vernais emails you, or select
Resend verification email. An account with no plan yet picks one. Then you reach workspace setup, because a new account has no workspace.
Google links itself to an existing password account on the same address only when that address is verified. If it is not, you see Sign in with your password to link Google to your account. Sign in with the password once. Google works after that.
Reset a password you forgot
A reset signs out every device you own — treat it as a full account reset, not a small repair.
- 1Select
Forgot password?It sits under the password field. Enter your email and select
Send reset link. - 2Read the reply carefully
It always says
If that email is registered, a reset link has been sent.Vernais never tells anyone whether an account exists, so nobody can fish for your address. - 3Open the link and pick a new password
The link works once, then expires.
- 4Sign in again
Setting the new password signs out every device, including the one you are on.
Create a workspace, or join your team's
A workspace is a sealed box. It holds one team's data, chats and knowledge graph in its own two private databases. Nothing inside one workspace is visible from another.
If your team already runs Vernais, join theirs — a workspace you create starts empty and inherits nothing from the one they built.
You name it and you own it. Vernais builds it blank: no chats, no data, no graph. You connect your tools and build the graph inside it. Your row is tagged created.
You paste the invite code a teammate sends you. You land in their workspace with everything already there. Your row is tagged joined.
- 1Pick
New workspaceorJoin with codeThe two cards sit at the top of the setup screen. When your account cannot create one, the cards are hidden and the join form is all you see.
- 2Name it, or paste the code
A new workspace also lets you pick a pixel logo. Both paths let you pick your avatar.
- 3Select
Create workspaceorJoin workspaceYou land inside it right away.
A workspace you create is genuinely empty. That is the design, not a fault. Next you connect a tool and build the graph inside it.
Create your own when you want a slice nobody else touches — a side product, a trial run, one client. The test: if a teammate could already ask Vernais why are checkouts dropping and get an answer, join them instead of starting over.
Super invite to lift the domain lockSuper invite code skips both checks, and an email invitation skips them tooFill in your profile
Go to Settings, then Profile. The four fields below show to everyone in your workspace.
- Avatar — a cartoon character. It shows on the sidebar, the member list, and everything you create.
- Display name — up to 80 characters.
- Role / title — up to 120 characters. It sits on your profile card for everyone in the workspace.
- About you — up to 300 characters, on the same card.
Role / title is free text on a card. It grants nothing. What you can actually do is a per-person permission set the workspace owner assigns — see permissions and seats.
Change your email or password
A password change signs out every other device — that is what makes it the right move the moment you suspect trouble.
Change your password
Settings → Login & security → Change password. Enter your current password, then the new one twice, then select Update password. Every other device is signed out. This device stays in.
Change your email address
Settings → Profile → Email address → Change email. Type the new address and your current password, then select Send confirmation link. The link goes to the new address, and the change only lands when you open it. The reply is deliberately neutral: If that address is available, a confirmation link has been sent.
Add a password to a Google account
A Google-only account has no password to change. Login & security offers Send password setup link instead. Adding a password does not disconnect Google — you can then use either one.
Check which devices are signed in
Read this list the day you lose a laptop — revoking a session cuts that device off at once.
Settings → Login & security → Active sessions lists every browser signed in to your account, your own device first.
| What you see | What it tells you |
|---|---|
| The label | The browser and device, worked out from the browser itself — Chrome on Mac, Safari on iPhone. |
| The IP address | Where that session signed in from. |
signed in and a date | When the session started. |
This device | The tag on the session you are reading this from. |
- Revoke one — select the icon at the end of its row. That device is signed out at once.
- Sign out everywhere else — select
Sign out of all other devices. It appears only when there is another one. This device stays in. - Sign out here — the
Sign outitem at the bottom of the settings rail. Your other devices stay signed in.
Leave a workspace, or delete your account
Three buttons sound alike and destroy very different things. Read the row before you pick one.
| Action | Where | What it destroys |
|---|---|---|
| Leave a workspace | Settings → Workspace → General → Danger zone | No data. You lose access until someone invites you back, and you land in another workspace you belong to, or on the setup screen. |
| Delete a workspace | The same danger zone, owner only | Both of that workspace's databases and all of its data, for everyone in it. Your account and your other workspaces are untouched. If the delete cannot finish, Vernais aborts it and leaves the workspace whole so you can retry. |
| Delete your account | Settings → Profile → Delete account | Your account, plus every workspace you own and all of its data, for everyone in it. Memberships in workspaces other people own are removed. |
An owner cannot leave the workspace they created — the danger zone offers Delete workspace instead. Ownership cannot be handed to anyone else, so who creates the workspace is a lasting decision.
Deleting your account cannot be undone. It also deletes every workspace you own, with all of its data, for everyone else in them. You confirm with your password and by typing DELETE. A Google-only account confirms with its session, because it has no password.
Related resources
Invite and manage your team
Send an invite, pick the seat it carries, then tune what that one person can do.
Two things decide what a teammate can do. Their seat sets the AI ceiling. Their permissions set everything else. You choose the seat when you invite them. You tune permissions after they join. There are no roles to pick — see Permissions and seats for the full model.
Pick the seat before you invite
Choose the seat with one question: does this person need to ask the AI anything?
| Seat | What it unlocks | Who it fits |
|---|---|---|
| Max seat | Everything a Power seat gets, plus AI chat, the agent and root-cause investigations | A PM who asks questions and runs investigations |
| Power seat | Data, dashboards and the knowledge-graph browser. No AI chat, no agent, no investigations. | Someone who reads what others found |
The seat is a hard ceiling. Vernais takes the permission set you assigned and strips the three AI capabilities out of it unless the person is on a Max seat: chat.use, investigation.run and codebase.analyze. In the permission editor those three toggles sit greyed out on a Power seat, tagged ⚡ Max seat. No other grant buys AI back.
Only the workspace owner can change a seat. If you hand someone team management, they can edit other people's permissions — the seat stays with you.
Invite someone by email
- 1Open the invite panel
Go to Team, then select
Invite member. Email, the shared code and Super invite all live in this one panel. - 2Enter their address
Type it into
Email address. The invitation works for that exact address and no other. - 3Choose the seat
Pick
Max seatorPower seatin theSeatfield. It is the only choice the invitation carries, and it defaults to Max. - 4Send it
Select
Send invite. They appear underPending invitationsuntil they accept.
The invitation is single-use and locked to that address. When they accept, they join with the seat you chose plus the default rights described below. To pull an invite back before it is used, select Revoke on its row — the link stops working at once.
Share one invite code instead
Reach for the code when several people join at once and they all need the same seat.
- 1Set the joiner seat
Team →
Invite member→Share an invite link. SetNew members join with this seat, then selectSave. - 2Copy the code
Select
Copy. Anyone who enters that code joins with the seat you saved. - 3Read the line underneath
It states exactly who the code admits right now, so you don't have to guess.
By default the code only admits people whose email domain matches the owner's company domain, and their email has to be verified. If the owner signed up with a free provider like Gmail, there is no company domain — the code then admits nobody, and email invites are the only way in.
To let a contractor or anyone outside your company use the code, turn on Super invite. The code then accepts any email address. If the code leaks, select Regenerate: the old code stops working for anyone who has not joined yet, and people already in are untouched.
Email invites are better when seats differ per person, or when you want a record of who invited whom. The test: if you would give two people different seats, the shared code is the wrong tool.
Change what one person can do
Permissions are per person, edited from their row — there is no role to change and no matrix to maintain.
- 1Open their permission set
Team → Members. Select the permissions link on their row — it reads
N permissions · Manage, orFull accessfor the owner. - 2Toggle capabilities
Each capability is a checkbox, grouped by section: AI Chat, Products, Initiatives, Data, Team, Integrations, Storage, Billing and more. Use
Enable allorDisable allto move a whole section. - 3Read the tags
A
defaulttag marks an ordinary right that is on the day someone joins. A⚡ Max seattag marks an AI capability, greyed out on a Power seat. Analways ontag marks a right nobody can revoke. - 4Save
Select
Save permissions. The change applies to their next request.
Capabilities come in three kinds, and knowing which is which explains most surprises.
- Ordinary rights — viewing the dashboard, data, initiatives, pages, the calendar. On the moment someone joins.
- AI rights — chat, investigations, codebase analysis. On by default too, but they survive only on a Max seat.
- Manage rights — connecting a tool, running the brain, editing any initiative, managing the team, workspace settings, billing. Off until you turn them on for that person.
Turning a capability off hides that section from them. It does not grey out a dead button — their sidebar is shorter. That is why a teammate reporting "I can't see Chat" is usually a seat problem, not a permission one.
One toggle is locked on for everyone: personal settings. That is how a person reaches their own profile and signs out, so tightening permissions can never trap someone with no way out.
You cannot edit the owner's permissions — the person who created the workspace always holds every one of them. A teammate you granted team management can edit other people but never themselves, and can only hand out permissions they already hold. Nobody can promote themselves that way.
Remove someone
- 1Find them
Team → Members. Search by name or email if the roster is long.
- 2Remove
Select the trash icon on their row and confirm.
- 3Check what happened
They lose access on their next request and need a fresh invite to come back. Their seat frees up for someone else.
Only the workspace owner can remove a member, and the owner can't be removed. There is no ownership transfer, so whoever creates a workspace keeps it — pick that person deliberately.
Related resources
Permissions and seats
Two dials decide what a person can do in Vernais: their seat, then their permissions. The seat is checked first, and it can veto everything else.
Vernais has no roles. There is no admin, no manager, no viewer. The workspace owner hands each person their own list of capabilities, one by one. On top of that sits a seat, which is a billing ceiling.
Read the two dials in this order. The seat says whether a person can touch the AI at all. The permissions say which sections and actions they get. An AI permission that the seat forbids does nothing.
Seats: the AI ceiling
A Power seat has no AI. No permission can give it back.
Every member holds one of two seats. This is the hard billing line, so only the workspace owner can move someone between them. A person whose seat has never been set counts as Max.
| Seat | What it unlocks | What it never gets |
|---|---|---|
| Max seat | AI chat, the agent, web and research, root-cause investigations, codebase analysis, plus all their data access | Nothing — the ceiling is open |
| Power seat | Data, the knowledge graph, dashboards, initiatives, reports, pages, live chat, calendar | AI chat, investigations, codebase analysis — permanently |
The mechanism is short. Vernais takes the person's assigned permissions, then deletes the AI ones unless the seat is Max. In the code the seats are stored as chat (Max) and power.
You can see this in the permission editor. Every AI capability carries a ⚡ Max seat tag. On a Power seat those three checkboxes are also greyed out, so you cannot tick them at all. If they were ticked before the seat changed, they stay stored and stop working.
A Power seat also loses the Chat & AI pane in Settings. Panes are hidden, not greyed out, so the person will not see an option they cannot use.
Permissions: assigned per person
The owner ticks boxes for one human being at a time. There is no role to copy.
Open the Team section, find the person's row, then click the permissions link on it — it reads N permissions · Manage. A modal lists all 37 capabilities, grouped by section. Tick what that person needs and save. The list you save becomes their whole permission set.
Each section is gated by one right. Switch that right off and the section vanishes from their sidebar — no error message, no greyed-out button. The other rights inside a section hide an action rather than the section: turning off Create initiatives leaves Initiatives visible and takes the button away.
The three tiers
Each capability carries a tier. The tier tells you what the capability is, not who gets it.
Ordinary view and use rights. On for a brand-new member. The owner can switch any of them off for one person.
AI chat, root-cause investigations, and codebase analysis. Seat-gated: they work on a Max seat and never on a Power seat.
The manage and admin powers — edit products, connect tools, run the brain, manage the team, workspace settings, billing. Off by default. The owner grants them per person.
A new teammate you have not configured starts with baseline plus AI — 23 capabilities. On a Max seat they can chat on day one. On a Power seat the ceiling strips the AI three, leaving the 20 baseline rights.
Their real access is the set the owner assigned, minus the AI rights their seat forbids.
The permission catalog
These are the 37 capabilities, grouped by section in the order the editor shows them.
| Capability | Section | Tier |
|---|---|---|
| AI chat / agent / web / research | AI Chat | AI |
| Run root-cause investigations | AI Chat | AI |
| View the dashboard | Dashboard | Baseline |
| Your own task queue | My Tasks | Baseline |
| Your own inbox | Inbox | Baseline |
| View product details | Products | Baseline |
| Edit products + New product | Products | Elevated |
| View initiatives | Initiatives | Baseline |
| Create initiatives | Initiatives | Baseline |
| Edit initiatives you own/report | Initiatives | Baseline |
| Update your assigned task status | Initiatives | Baseline |
| Edit ANY initiative (override) | Initiatives | Elevated |
| Take Measure actions on any initiative | Initiatives | Elevated |
| View launch tracking | Launches | Baseline |
| Take a reading on any launch | Launches | Elevated |
| Use live chat (public + own private) | Live Chat | Baseline |
| Create / delete channels | Live Chat | Elevated |
| Create / view / edit pages per permission | Pages | Baseline |
| Use the calendar | Calendar | Baseline |
| Browse the KG data / graph | Data | Baseline |
| Add a new node | Data | Elevated |
| View reports | Reports | Baseline |
| Update any report | Reports | Elevated |
| See the member list | Team | Baseline |
| Invite / remove / seat / permissions | Team | Elevated |
| See public workspace activity | Activity | Baseline |
| Connect / sync / disconnect / purge | Integrations | Elevated |
| Run Corvex manually | Integrations | Elevated |
| Analyze approved or user-provided codebases | Codebase | AI |
| Choose the GitHub repo for technical task analysis | Codebase | Elevated |
| See all members' files + who uploaded | Storage | Elevated |
| See your own upload usage | Storage | Baseline |
| See your own seat | Billing | Baseline |
| Manage plan / payment | Billing | Elevated |
| Workspace settings / members / invites | Settings | Elevated |
| Your own personal settings | Settings | Baseline · always on |
| Help & docs | Help | Baseline |
Your own personal settings can never be switched off, by anyone. It is how a person reaches their profile and signs out. Tightening permissions can never trap a teammate with no way out.
One pairing is worth knowing. Any initiative capability quietly adds View initiatives when you save, because you cannot act on what you cannot see.
What the owner can always do
The owner is the person who created the workspace. That is permanent — there is no way to hand ownership to someone else.
- Hold every permission. All 37, always. The owner cannot be locked out.
- Stay uneditable. Nobody can change the owner's own permissions, including the owner.
- Change any seat. Moving a person between Max and Power is owner-only, because the seat is the billing ceiling.
- Grant anything. The owner is not bounded by their own set the way a delegate is.
- Delete the workspace. An owner cannot leave a workspace. Deleting it is the only exit.
You can delegate the roster. Grant Invite / remove / seat / permissions and that person can invite, remove and set permissions for everyone else. Three limits still hold. They cannot edit their own permissions. They cannot grant a right they do not hold themselves. And despite the word seat in that label, they cannot change a seat — that stays with the owner.
Limits
Team → the person's row → the Seat dropdownInvite / remove / seat / permissions and the elevated rights they needWhen someone cannot see a section
Sections are hidden rather than disabled, so there is no error message to read. Check in this order — it is the same order the code checks.
- Seat first. If the whole Chat section is missing, look at their seat. A Power seat strips AI chat, investigations and codebase analysis together, and no permission will fix it.
- Permission second. Open their row in
Teamand clickManage. A section disappears when its gate right is off —View initiativesfor Initiatives,Browse the KG data / graphfor Data,View reportsfor Reports. - Then the pane. Settings panes follow the same rule.
Members & permissionsandInvitationsneed team management,GeneralandWorkflowsneed workspace settings,Codebaseneeds the repo-choosing right, andChat & AIneeds AI chat.
AI chat is ticked for this person, so why can't they use it?
Seat dropdown on their row in Team.Can I give someone the same access as a teammate?
Enable all shortcut.Can I transfer the workspace to someone else?
Related resources
What the AI can see
A workspace is a wall. Here is exactly what sits on each side of it, and why your new one opened empty.
One constraint shapes most of what follows: when Vernais answers from your connected data, every claim has to trace back to a record it can point at. It will not invent a cause. A question it cannot ground in your data returns nothing rather than a guess. Questions about the outside world, or about general knowledge, it answers like any good assistant — and tells you which world the answer came from.
So "what can the AI see?" has an exact answer. It sees the records in the workspace you are in right now. Not your account. Not the workspace you were in this morning. This page maps that line.
What a workspace actually is
A workspace is two private databases, and Vernais builds them empty.
When you create a workspace, Vernais creates two databases named after it. One holds your working data: chats, initiatives, files, activity. The other holds the knowledge graph. It copies the shape of the global setup — the table names and the columns — and copies none of the contents.
That matters more than it sounds. A second workspace is not a view, a filter, or a folder. It is a separate store. Data cannot leak across it, because a query run in one workspace never names the other database at all.
Deleting a workspace drops both of its databases. The chats, the graph, the initiatives and the activity go with it, for everyone in it, with no undo. Only the workspace owner can do it.
What stays inside one workspace
If your team's work produced it, it stops at the workspace line.
| What | What that means |
|---|---|
| Knowledge graph | Every record the AI learned from, and the entities and topics built on top. Corvex writes into the workspace you ran it in, and nowhere else. |
| Chats | Threads and messages live in that workspace's database. |
| Memory | What the AI picks up about your work is written to the active workspace. It does not ride along with your account. |
| Initiatives | The problems you are working, with their hypotheses, evidence and tasks. |
| Activity log | Who did what. Each workspace keeps its own feed. |
| Files | Uploads and folders in Storage. |
| Tool connections | The credentials, and whether a tool reads as connected. Most people expect this one to be shared. It is not. |
Memory deserves a second look, because it surprises people who use two workspaces. Tell the AI something useful in one workspace and it writes that to that workspace's database. Ask about it from another workspace and it has no idea. The write refuses to run at all if no workspace is active, rather than fall back to a shared store. See What it knows about you.
You connect each tool again in every workspace
A connection belongs to a workspace, not to your account.
This is the one that catches people, because the tool list looks shared. The catalog is global: every workspace shows the same set of supported tools, with the same logos. The connection is not. Each connection record carries the id of the workspace that made it, and every screen filters to your workspace before it draws a single card.
So a tool you connected last week in one workspace reads as not connected in the next one. The credentials do not travel, and the records they pulled do not travel either. A second workspace means connecting the tools again, syncing them, and running Corvex there. See Connect a tool and Build the graph.
Splitting into separate workspaces is not always right. Each one is another set of tools to connect, another sync, and another Brain run — and no single question can ever reach across two of them. The test: if you would ever want one investigation to read both sets of data, they belong in one workspace.
Switching workspaces changes every answer
Check which workspace you are in before you trust a number.
Switching re-points the whole app. Every section drops what it was holding and re-fetches from the new workspace's databases. The AI does the same. An investigation, a data lookup, or a chat question runs against the workspace that is active when you press send.
The honest consequence: the same question can give two different answers in two workspaces, and both are correct. One workspace has Stripe and Sentry synced. The other has nothing yet. The second one says it has no evidence, which is the right answer for the data in front of it. See When it finds no evidence.
What the line does not cover
Three things sit outside the workspace, and knowing which is which saves a lot of confusion.
- Your account — your name, avatar, password and signed-in devices belong to you, across every workspace you are in.
- The tool catalog — the list of supported tools is the same everywhere. Only the connections are scoped.
- General knowledge and the web — a workspace walls off your data, not the AI's ability to think. It will still explain a concept or search the web, and it tells you the answer came from there and not from your records.
Common questions
Why is my new workspace empty?
Why does it say a tool is connected when I never connected it here?
I switched workspaces and the AI forgot what I told it. Is that a bug?
Can I ask one question that spans two of my workspaces?
Related resources
See who did what
The Activity log answers one question: who did what in this workspace, and when. Every entry is timestamped, and no code path edits or deletes one.
What the activity log is
Vernais writes an entry each time someone changes the workspace. Creating an initiative. Connecting a tool. Running the Brain. Each entry holds the actor, the action, the time, and the thing it touched. The log is append-only. The code inserts entries and nothing else — there is no update path, no delete path, and no button that edits one. What you read is what happened.
The log records that an action happened, not the content it produced.
What gets logged
| Type | What triggers an entry | Who can see it |
|---|---|---|
| Initiatives | Create or delete one, reassign the owner, lock a metric, anchor a hypothesis, pick a solution, attach a file | Everyone |
| Act tasks | Start Act, create or move a task, file a bug, merge a branch, scan Sentry | You only |
| Products | Create or delete a product | Everyone |
| Pages | Create, edit or delete a page or folder | Everyone for public pages. You only for the rest. |
| Investigations | Start an investigation | You only |
| Integrations | Connect, sync, disconnect, purge, change settings or a webhook | Owner and team managers |
| Data | Run Corvex pipeline | Owner and team managers |
| Web scrapes | Start a scrape | Owner and team managers |
| Workspace | Create, join, rename, leave, regenerate the invite code | Owner and team managers |
| Team | Change a role or seat, edit permissions, invite or remove a member | Owner and team managers |
| Storage | Upload a file, create or delete a folder | You only |
| Live chat | Create or delete a channel | You only |
| Account | Sign in or out, change your password or email | You only, always |
Chat writes no entry at all. Asking the AI a question logs nothing, and no message text is stored here. Elsewhere the entry names the thing, not the work inside it. A page entry names the page, never its body. An integration entry names the tool, never the records it pulled. Two entries do carry your words. An investigation stores its question, and a scrape stores its query. Both sit in the detail line, capped at 600 characters.
Who sees what
Shared work on shared objects — initiatives, products, reports, public pages. Any member with the Activity permission reads these. That permission is baseline, so every role has it.
The default. An action lands here unless the code marks it shared or management. Your logins, uploads and investigations are yours alone. Account entries stay private even from the owner.
The control plane — workspace, team, integrations, Brain runs, scrapes, codebase. A platform admin, the workspace owner, or anyone with Manage team reads these.
A meeting transcript entry reaches the people on that invite and nobody else. It stays out of everyone else's counts too.
Visibility follows the action, not the type — an Act task is typed Initiatives but stays private to you.
Find an event
- 1Search by person, action or target
The box matches the entry title, the detail line, the actor's name and the target label. It waits 280ms after you stop typing, then runs. It does not match the action id or the meta chips.
- 2Narrow by type
The dropdown beside the search box lists only the types your workspace has, each with its own count.
- 3Read the day and time
The When column carries a day label — Today, Yesterday, a weekday, then a date — next to a relative time. Hover it for the full timestamp.
- 4Open the row
Click any row. A drawer shows the actor, action, detail, type, target id and the exact time. Meta values land here too, like a scrape's page count and intensity.
- 5Load more
The feed starts at 40 events and appends 40 at a time.
Reach for the type filter when you are surveying — 'what changed in integrations this week'. It gives you a clean, countable slice, and it runs in the database rather than over the rows on screen. The counter-case: when you know a name or a phrase, search lands on the row in one step. A type guess can send you to the wrong slice. Report events, for instance, sit under Other. Test: can you name the type without thinking? Filter. If not, search.
The three numbers at the top
Every event in this workspace you are allowed to see, across all pages. The type filter and the search do not change it.
Distinct actors among the rows loaded right now — not across the whole log. Load more raises it.
How long ago the newest loaded event happened.
