Skip to Content
OperationsWorkspace governance

Workspace governance

Engage separates workspace governance from environment messaging operations.

Engage workspace team management with members, roles, invitation state, and access operations
Workspace membership and invitations are managed separately from environment audiences and app installations.

Roles and permissions

Grant permissions by job responsibility. Important boundaries include read versus edit, publish/send, integrations management, analytics/export access, privacy operations, security/team administration, audit, and billing.

Do not use shared administrator accounts. Identity, MFA/OIDC settings, session security, and role assignment should identify the operator responsible for each change.

Engage workspace role management with permission groups and role assignments
Role definitions make publish, send, integration, privacy, analytics, security, and billing boundaries reviewable.

Audit

Audit records support investigation of access, environment/app changes, credential management, content publication, sends, automation lifecycle, privacy actions, exports, retention, billing, and security changes. Keep actor, timestamp, resource, action, and safe metadata; never store plaintext secrets in audit details.

Engage workspace audit log with actor, action, resource, timestamp, environment, and safe change metadata
Audit records connect privileged operations to an actor and resource without exposing plaintext secrets.

Usage and quotas

Environment usage includes API requests, audience/event processing, sends/deliveries, automation work, media, exports, and other metered capabilities. Surface warning and blocked states before an operation fails unexpectedly.

Billing

Workspace billing may use the configured provider or self-managed mode. Plan entitlements and quotas gate product operations; billing webhooks and provider calls are idempotent. Restrict billing access separately from messaging permissions.

Engage workspace billing view with plan, usage, entitlement, invoice, payment, and billing status
Billing and entitlements remain a workspace concern even when quotas are surfaced in environment operations.

Retention

Retention policy applies to profiles/events, delivery diagnostics, webhook attempts, exports, analytics facts, and audit according to product/legal requirements. Short retention can reduce investigation depth; excessive retention increases privacy exposure.

Production readiness

  • Configure OIDC/MFA/team roles.
  • Set production secret encryption keys.
  • Create least-privilege access keys and webhook secrets.
  • Validate provider credentials and worker health.
  • Define quotas, alert ownership, retention, and privacy process.
  • Verify audit visibility and billing state.
  • Exercise incident rotation/revocation before launch.