Team, roles and account

Organizations and workspaces, the Owner, Admin, Member and Viewer roles, invitations, leaving and transferring, deleting a workspace, passwords, signing out everywhere and e-mail language.

Workspaces are organizations

A workspace is an organization: it has its own decisions, API keys, members, secrets, settings, plan and billing. API keys belong to one workspace, and nothing is shared between workspaces.

  • Switch workspaces from the workspace menu at the top of the sidebar; it shows your role in each one.
  • Create one with Create workspace in that menu. You become its Owner, and it starts on the free Genesis plan. You can own up to 10 workspaces.
  • Every account keeps at least one workspace. If you leave your last one, are removed from it or it is deleted, you get a new personal workspace — "Ana's workspace" — so you never land in an empty app.

Organization details

Settings → Organization holds the company behind the workspace — Admins and the Owner can edit it:

FieldRules
Legal nameUp to 160 characters.
Tax IDUp to 40 characters: letters, digits, ., /, - and spaces — a CNPJ, a VAT number…
Billing e-mailA valid e-mail address.
CountryThe 2-letter country code, such as BR or US.
AddressLine 1, line 2, city, state and postal code.
WebsiteA full https:// URL.

Once the workspace has a Stripe customer — after its first checkout — saving these details updates it: the legal name (or the workspace name), the billing e-mail, the address, and the tax ID printed on every invoice. Dcision's own billing and quota e-mails go to the workspace's Owner.

Roles

Every member has one role. Each role can do everything the roles above it in this table can, and more:

RoleCan
ViewerRead decisions, executions, usage and members. Manage their own account. Leave the workspace.
MemberAlso create, edit, deploy and run decisions, and manage API keys and destinations.
AdminAlso invite, remove and change the role of Members and Viewers; edit the organization details, the workspace name and its log retention; manage provider keys and destination secrets.
OwnerAlso manage billing and credits; invite, promote and remove Admins; transfer ownership; delete the workspace.

In detail:

ActionViewerMemberAdminOwner
See decisions, versions, executions — stored inputs included — usage, the Overview and deliveries✓✓✓✓
See the members, the plan, the usage of the period and the credits✓✓✓✓
Create, edit, duplicate, deploy, disable and delete decisions—✓✓✓
Run decisions in the Playground—✓✓✓
Create, rename and revoke API keys—✓✓✓
Edit destinations, see secret names, resend failed deliveries—✓✓✓
Invite Members and Viewers; change their role; remove them——✓✓
Edit the workspace name, log retention and organization details——✓✓
Engine settings and provider keys——✓✓
Workspace secrets and the signing secret——✓✓
Invite, promote, demote and remove Admins———✓
Billing: plans, checkout, cancellation, payment methods, invoices———✓
Credits: buy, save a card, automatic recharge, spend cap, vouchers———✓
Transfer ownership; delete the workspace———✓
Leave the workspace✓✓✓—

A few rules always hold: a workspace has exactly one Owner; nobody changes their own role; the Owner role moves only through a transfer, and nobody can remove the Owner; only the Owner grants or takes away the Admin role.

Refusals answer 403 FORBIDDEN with a message that names the role needed — "Viewers can't change anything in this workspace. Ask an admin for the Member role.", "Only workspace admins can do this.", "Only the workspace owner can do this." When you are no longer a member of the workspace at all, the error carries details.reason = "workspace_access" and the app switches you back to a workspace you belong to. See Errors.

Roles apply to the app. API keys are not people: a key can run every decision of its workspace and read its account and executions, whoever created it.

Invitations

Invite

In Settings → Members, enter an e-mail under Invite by e-mail, pick the role — Member or Viewer; the Owner can also invite Admins — and send. Owners are never invited: ownership is transferred later.

The e-mail

The person receives a link to https://app.dcision.io/invites/…, valid for 7 days. The e-mail is in their language when they already have an account, otherwise in yours. Names typed by people — the workspace's, the inviter's — are shown as plain text: links are removed and domain names can't be clicked, so an invitation can't carry a phishing message.

Accepting

  • At sign-in: every pending invitation for the person's e-mail is accepted automatically — with Google, an e-mail code or a password. Someone who signs up through an invitation joins the team's workspace and gets no personal one.
  • With the link, signed in with the invited e-mail address. The page tells when the invitation was already accepted, revoked or expired, or was sent to another address — without revealing that address.

Pending invitations are listed under Members: Resend sends a new link — the previous one stops working — and Revoke cancels it. Only a hash of each link's token is stored.

Limits: 30 invitations per hour, per workspace and per person, and 50 pending invitations per workspace. Inviting someone who is already a member fails with 409 CONFLICT.

Leave, remove, transfer, delete

ActionWhoWhat happens
Leave the workspaceAnyone but the OwnerYou lose access at once; an Admin can invite you again. The Owner transfers ownership first — or deletes the workspace.
Remove a memberAdmins remove Members and Viewers; the Owner also removes AdminsThe person loses access at once. The decisions and API keys they created stay.
Transfer ownershipThe Owner, to any memberThe member becomes the Owner; the previous Owner becomes an Admin.
Delete the workspaceThe Owner, typing the workspace slug in Settings → Danger zoneDeletes its decisions, versions, executions, API keys, invitations, secrets and deliveries for everyone, and can't be undone. Members without another workspace get a new one.

A workspace with a live paid subscription can't be deleted: cancel it in Billing and delete the workspace after the subscription ends. Its Stripe customer is kept, so past invoices stay available.

Your account

Account holds what belongs to you, in every workspace — even as a Viewer.

Signing in

Sign in with Google, with a 6-digit code sent by e-mail, or with a password if you set one.

  • E-mail codes are valid for 10 minutes and 5 attempts. An e-mail address can receive 3 codes every 10 minutes and 10 a day, and a new code replaces the previous one.
  • Each network can request 10 codes and make 30 sign-in attempts every 10 minutes.
  • Sessions last 30 days.

Password

A password is optional — set it in Account → Password:

  • 10 to 128 characters, with letters and numbers;
  • it can't contain your e-mail address, and common or repetitive passwords such as password123 are refused.

Sign-in with a password gives the same answer for an unknown e-mail and a wrong password. After 5 wrong attempts, wait 15 minutes — or sign in with an e-mail code. Changing a password requires the current one and signs out every other session. Setting or changing it always sends you an e-mail, so a stolen session can't add a password silently.

Sign out everywhere

Lost a device or used a shared computer? Account → Sessions → Sign out everywhere ends every session of your account, the current one included.

Language

Account → Language sets the language of the e-mails Dcision sends you — sign-in codes, invitations and security notices — in English, Portuguese, Spanish, Russian or Chinese (en, pt, es, ru, zh). It starts from your browser's language when you sign up; your choice wins afterwards. Billing and quota e-mails are in English, and the app interface is being translated.

On this page