Team Workspaces & Permissions
Share servers and their SSH credentials with teammates through an encrypted workspace, and scope exactly which servers and apps each role can reach.
What Team workspaces do
Team workspaces let you "share infrastructure access without sending credentials in chat." A server's SSH credentials move into an encrypted, storage-backed workspace, and you scope per-member access from there. Open it from the sidebar's Team tab. Team requires an active Pro license. Without one: "Team workspaces require an active Pro license. Existing shared data stays visible, but mutations are read-only."
Create or join a workspace
Use New workspace or Join. The dialog asks for:
- Workspace name
- Recovery passphrase (at least 12 characters)
- Your display name
- Invite code (a full SCTW1 code, when joining)
- Storage destination
Storage must be S3-compatible — "conditional writes are what stop two people from overwriting each other." SFTP, Google Drive, and pCloud cannot host a Team workspace.
Roles and per-server grants
Workspaces have four roles: owner, admin, member, and viewer. Owners and admins inherit every shared server and cannot be narrowed per server; members and viewers get explicit grants. On the Permission tab ("Who can reach which server"), Share a server moves its SSH credential into the encrypted Team vault. Choose a share mode — Use only or Use and reveal — then grant access in the matrix: Whole server or individual apps, with an optional Expires time. "Grants are checked at every action. Desktop, remote, and MCP all honour expiry."
Frequently Asked Questions
Do teammates see my SSH keys?
Only if you share a server with "Use and reveal". With "Use only", members can act on the server without the raw credential being exposed to them.
Does Team require Pro?
Yes. Team workspaces require an active Pro license; without one, shared data stays visible but becomes read-only.
Ready to try Server Compass?
Download the app and deploy your first application in under 5 minutes.
Download Server Compass