Skip to content

Workspaces and members

A workspace is one self-contained InfraInbox: its own sources, rules, destinations, incidents and members. Nothing is shared between two of them, and nothing you do in one is visible from the other. Most homelabs need exactly one; a second is useful for a separate site, a client, or somewhere to try a rule change without touching the real thing.

The workspace you are in is the row under the mark at the top of the navigation (on a phone, the name beside the ☰ button). Open it and every workspace you belong to is listed, with the one you are looking at marked.

Choosing another one switches the whole dashboard: every list is read again for that workspace, live updates reconnect, and you land on its inbox. Times move too — each workspace has its own time zone, and every date in the dashboard is shown in the zone of the workspace you are in.

A switch is per browser tab and is not remembered: a new tab starts in your first workspace again.

In the same menu, choose New workspace. It asks for two things:

  • a name, which is what the dashboard and your notifications call it;
  • a time zone, an IANA name such as Europe/Bucharest. It is what quiet hours and a rule’s “at 08:00” mean by a wall clock, so it is worth getting right — your browser’s zone is suggested. You can change it later under Settings → Workspace.

You land in the new workspace, as its owner, with its zone in effect.

Every member of a workspace has one role.

Role Can
Owner Everything an admin can, plus manage members: invite, change roles, remove.
Admin Change the workspace’s settings, sources, API keys, destinations and notification rules.
Member Read everything, and work the inbox: acknowledge, snooze and resolve incidents.

Everyone, whatever their role, has their own account, security and devices settings, and everyone can read the member list.

Under Settings → Members, an owner types an address, picks the role, and chooses Invite.

The invitation link is then shown once. Its secret sits after the # in the address, so it never reaches a server log, a proxy’s or another site — and for the same reason InfraInbox cannot show it to you again. Copy it before you close the dialog. If the server can send mail, it is emailed to the address as well; if not, pass it on yourself, the way you would a password.

An invitation works once, for that one address, and expires — the Pending invitations list shows when. An owner can Revoke one at any time, which stops the link working immediately; to replace a link that went astray, revoke it and invite again.

Open the link. You need to be signed in to the account that uses the invited address, so if you are not signed in yet, sign in first and then open the link again. Accepting puts you straight into the workspace, with its time zone in effect.

On InfraInbox Cloud, somebody invited who has no account yet does not need a beta code: the invitation stands in for one. Paste its link into the sign-up page, confirm the address, sign in, and open the invitation link again to accept it.

A link that has been used, revoked, has expired, or was sent to a different address than the one you are signed in as, all say the same thing — it is not valid — and there is nothing to be done with it but ask an owner for another. Only the account at the invited address can accept, so a link that went to the wrong person is useless to them.

On the same screen, an owner changes a member’s role with the control on their row, or removes them with Remove. Both are sensitive, so InfraInbox asks you to confirm it’s you first — your password, or your authenticator code.

Two things the screen will not offer:

  • the last owner. A workspace must keep at least one owner, or nobody could invite or change anything again, so the only owner’s role and removal are not on offer. Promote a second owner first.
  • your own membership. Another owner removes you; v0.1 has no way to leave a workspace by yourself, and no way back in without a fresh invitation.

Removing someone takes their access away at once. Their own account, its password and its paired phones are untouched — they simply no longer belong to this workspace.