Team, roles and account
Organizations and workspaces, the Owner, Admin, Member and Viewer roles, invitations, leaving and transferring, deleting a workspace, passwords, signing out everywhere and e-mail language.
Workspaces are organizations
A workspace is an organization: it has its own decisions, API keys, members, secrets, settings, plan and billing. API keys belong to one workspace, and nothing is shared between workspaces.
- Switch workspaces from the workspace menu at the top of the sidebar; it shows your role in each one.
- Create one with Create workspace in that menu. You become its Owner, and it starts on the free Genesis plan. You can own up to 10 workspaces.
- Every account keeps at least one workspace. If you leave your last one, are removed from it or it is deleted, you get a new personal workspace — "Ana's workspace" — so you never land in an empty app.
Organization details
Settings → Organization holds the company behind the workspace — Admins and the Owner can edit it:
| Field | Rules |
|---|---|
| Legal name | Up to 160 characters. |
| Tax ID | Up to 40 characters: letters, digits, ., /, - and spaces — a CNPJ, a VAT number… |
| Billing e-mail | A valid e-mail address. |
| Country | The 2-letter country code, such as BR or US. |
| Address | Line 1, line 2, city, state and postal code. |
| Website | A full https:// URL. |
Once the workspace has a Stripe customer — after its first checkout — saving these details updates it: the legal name (or the workspace name), the billing e-mail, the address, and the tax ID printed on every invoice. Dcision's own billing and quota e-mails go to the workspace's Owner.
Roles
Every member has one role. Each role can do everything the roles above it in this table can, and more:
| Role | Can |
|---|---|
| Viewer | Read decisions, executions, usage and members. Manage their own account. Leave the workspace. |
| Member | Also create, edit, deploy and run decisions, and manage API keys and destinations. |
| Admin | Also invite, remove and change the role of Members and Viewers; edit the organization details, the workspace name and its log retention; manage provider keys and destination secrets. |
| Owner | Also manage billing and credits; invite, promote and remove Admins; transfer ownership; delete the workspace. |
In detail:
| Action | Viewer | Member | Admin | Owner |
|---|---|---|---|---|
| See decisions, versions, executions — stored inputs included — usage, the Overview and deliveries | ✓ | ✓ | ✓ | ✓ |
| See the members, the plan, the usage of the period and the credits | ✓ | ✓ | ✓ | ✓ |
| Create, edit, duplicate, deploy, disable and delete decisions | — | ✓ | ✓ | ✓ |
| Run decisions in the Playground | — | ✓ | ✓ | ✓ |
| Create, rename and revoke API keys | — | ✓ | ✓ | ✓ |
| Edit destinations, see secret names, resend failed deliveries | — | ✓ | ✓ | ✓ |
| Invite Members and Viewers; change their role; remove them | — | — | ✓ | ✓ |
| Edit the workspace name, log retention and organization details | — | — | ✓ | ✓ |
| Engine settings and provider keys | — | — | ✓ | ✓ |
| Workspace secrets and the signing secret | — | — | ✓ | ✓ |
| Invite, promote, demote and remove Admins | — | — | — | ✓ |
| Billing: plans, checkout, cancellation, payment methods, invoices | — | — | — | ✓ |
| Credits: buy, save a card, automatic recharge, spend cap, vouchers | — | — | — | ✓ |
| Transfer ownership; delete the workspace | — | — | — | ✓ |
| Leave the workspace | ✓ | ✓ | ✓ | — |
A few rules always hold: a workspace has exactly one Owner; nobody changes their own role; the Owner role moves only through a transfer, and nobody can remove the Owner; only the Owner grants or takes away the Admin role.
Refusals answer 403 FORBIDDEN with a message that names the role needed — "Viewers can't change anything in this workspace. Ask an admin for the Member role.", "Only workspace admins can do this.", "Only the workspace owner can do this." When you are no longer a member of the workspace at all, the error carries details.reason = "workspace_access" and the app switches you back to a workspace you belong to. See Errors.
Roles apply to the app. API keys are not people: a key can run every decision of its workspace and read its account and executions, whoever created it.
Invitations
Invite
In Settings → Members, enter an e-mail under Invite by e-mail, pick the role — Member or Viewer; the Owner can also invite Admins — and send. Owners are never invited: ownership is transferred later.
The e-mail
The person receives a link to https://app.dcision.io/invites/…, valid for 7 days. The e-mail is in their language when they already have an account, otherwise in yours. Names typed by people — the workspace's, the inviter's — are shown as plain text: links are removed and domain names can't be clicked, so an invitation can't carry a phishing message.
Accepting
- At sign-in: every pending invitation for the person's e-mail is accepted automatically — with Google, an e-mail code or a password. Someone who signs up through an invitation joins the team's workspace and gets no personal one.
- With the link, signed in with the invited e-mail address. The page tells when the invitation was already accepted, revoked or expired, or was sent to another address — without revealing that address.
Pending invitations are listed under Members: Resend sends a new link — the previous one stops working — and Revoke cancels it. Only a hash of each link's token is stored.
Limits: 30 invitations per hour, per workspace and per person, and 50 pending invitations per workspace. Inviting someone who is already a member fails with 409 CONFLICT.
Leave, remove, transfer, delete
| Action | Who | What happens |
|---|---|---|
| Leave the workspace | Anyone but the Owner | You lose access at once; an Admin can invite you again. The Owner transfers ownership first — or deletes the workspace. |
| Remove a member | Admins remove Members and Viewers; the Owner also removes Admins | The person loses access at once. The decisions and API keys they created stay. |
| Transfer ownership | The Owner, to any member | The member becomes the Owner; the previous Owner becomes an Admin. |
| Delete the workspace | The Owner, typing the workspace slug in Settings → Danger zone | Deletes its decisions, versions, executions, API keys, invitations, secrets and deliveries for everyone, and can't be undone. Members without another workspace get a new one. |
A workspace with a live paid subscription can't be deleted: cancel it in Billing and delete the workspace after the subscription ends. Its Stripe customer is kept, so past invoices stay available.
Your account
Account holds what belongs to you, in every workspace — even as a Viewer.
Signing in
Sign in with Google, with a 6-digit code sent by e-mail, or with a password if you set one.
- E-mail codes are valid for 10 minutes and 5 attempts. An e-mail address can receive 3 codes every 10 minutes and 10 a day, and a new code replaces the previous one.
- Each network can request 10 codes and make 30 sign-in attempts every 10 minutes.
- Sessions last 30 days.
Password
A password is optional — set it in Account → Password:
- 10 to 128 characters, with letters and numbers;
- it can't contain your e-mail address, and common or repetitive passwords such as
password123are refused.
Sign-in with a password gives the same answer for an unknown e-mail and a wrong password. After 5 wrong attempts, wait 15 minutes — or sign in with an e-mail code. Changing a password requires the current one and signs out every other session. Setting or changing it always sends you an e-mail, so a stolen session can't add a password silently.
Sign out everywhere
Lost a device or used a shared computer? Account → Sessions → Sign out everywhere ends every session of your account, the current one included.
Language
Account → Language sets the language of the e-mails Dcision sends you — sign-in codes, invitations and security notices — in English, Portuguese, Spanish, Russian or Chinese (en, pt, es, ru, zh). It starts from your browser's language when you sign up; your choice wins afterwards. Billing and quota e-mails are in English, and the app interface is being translated.
Plans, quotas and billing
Genesis, Developer, Growth and Enterprise — included decisions, prepaid credits past them, rate limits, decision and log limits — what is billed, and how credits, upgrades, downgrades, cancellations and invoices work.
CLI
The dcision command line — save an API key, run decisions, list templates, scaffold and validate decision schemas offline — with exit codes for scripts and CI.