Team setup guide

Permissions and approvals for a shared AI workspace

Decide who sees each Space, which tools AI can reach, and where a person signs off, before you invite the whole team.

A private Ops Space inside a dashed workspace frame, with three members, Stripe and HubSpot connections switched on, Gmail not assigned, and an approval card asking whether to add a Shopify connection.

What is a shared AI workspace with permissions and approvals?

It is one place where a team works with AI together, with controls for who can see each area of work, which tools the AI can use, and where a person must sign off before something changes.

Most teams start with AI one person at a time. Each person has a private chat, a private set of connected apps, and private prompts. That is safe enough, but nothing is shared, and nobody can review what the AI did for a colleague.

A shared AI workspace flips the default. Work happens in threads the team can read, the AI uses connections the team set up once, and recurring work runs on a schedule. That only works with a clear access model, because a shared workspace with loose permissions is riskier than a private chat.

This guide shows how to set up that model for an operations team in type.com: the layers that decide what AI can reach, a step-by-step setup, the approval points built into the product, and a test to run before you invite everyone.

For review of individual agent actions, such as a refund or a CRM update the agent proposes, see our companion guide: How to design AI agent approval workflows

Diagram of four nested access layers: workspace membership, Space access, thread or item sharing, and connections. A banner below states that AI acts with the effective access of the person and conversation that started the work.
Four layers decide what AI can reach. Each one narrows the layer above it.

Which permission layers does a team AI workspace need?

Four: workspace membership, Space access, thread and item sharing, and connections. AI then acts with the effective access of the person and conversation that started the work.

Every AI workspace has to answer the same questions. Who belongs to the company account? Which team areas can each person open? Which conversations and documents are private? Which tools can the AI use, and with whose credentials? In type.com, each question maps to a specific control.

The connection layer matters most. Adding a connection to the workspace does not give every Space access to it. You assign each connection to the Spaces that need it, and the connected service can still enforce its own permissions on top. AI does not gain broader access because a tool is connected somewhere else in the workspace.

Read type.com’s permissions and access documentation

Permission layers in type.com, from docs.type.com on October 2, 2026
LayerQuestion it answersControl in type.com
WorkspaceWho is in the company account?Admins invite members and set each active member as a member or admin.
SpaceWhich team area can someone open?Public Spaces are open to the workspace. Private Spaces are limited to people who were added. Sidekick is private to its owner.
ChannelDoes a channel add its own boundary?No. Channels follow their Space’s access rules.
ThreadCan one conversation stay private?A private thread is visible only to its participants, even in a public Space.
Documents and appsWho can open a shared item?Each item can be shared with specific people, private Spaces, the workspace, or a public link when workspace policy allows it.
ConnectionsWhich tools and credentials can AI use here?Personal or organization connections, assigned to specific Spaces.

How do you set up permissions for an ops team step by step?

Create a private Space for the team, add only its members, choose organization or personal connections on purpose, assign each one to the smallest set of Spaces, and write the team’s approval rules into the Space instructions.

The steps below assume an operations team that works with finance, CRM, and support data. Swap in your own tools, but keep the order. Access decisions are easier to get right before people start working in the Space than after.

Close-up of an Ops Space connection list: Stripe as a read-only organization connection shared with Finance, HubSpot as an organization connection shared with Sales, Google Drive limited to an Ops SOPs folder, and Dana’s personal Gmail connection not assigned to the Space. Callouts explain organization connections, read-only, and personal connections.
An illustrative Ops Space. Shared systems use organization connections, personal tools stay personal, and nothing is assigned beyond the teams that need it.
  1. 1

    Map the work to Spaces

    List the areas of work and who needs each one. A common split is one Space per team, such as Ops, Finance, and Sales, plus Sidekick for each person’s private work. Put work in the same Space only when the same people should see it.

  2. 2

    Create the Ops Space as private

    In Space settings, under Details, set the visibility to private and add the people who need it. Nobody else in the workspace can find or join it. Use public Spaces for work the whole company should see.

  3. 3

    Choose the connection type for each tool

    Use an organization connection for shared business systems such as a CRM, a support platform, or a warehouse. Use a personal connection where each person has their own permissions, such as email, calendars, and personal documents. A personal connection reaches only what that person can reach in the app.

  4. 4

    Pick an account with the right source permissions

    Before you connect, decide which account the connection will use. A service account or role limited to the team’s records is safer than an administrator login. The connected service still applies its own permissions, so this is where you set the real ceiling.

  5. 5

    Assign each connection to the smallest set of Spaces

    Open Space settings, then Connections, and add only what the team needs. A connection can be available for assignment across the workspace without being usable in every Space. For Google Drive, choose the specific files and folders the Space may read or update.

  6. 6

    Mark tools read-only where the team only reads

    Read-only tells the agent not to make changes. It does not block changes at the connected service, so pair it with a read-only role or key in the tool itself when the risk is real.

  7. 7

    Write the approval rules into the Space instructions

    type.com includes the Space instructions with every message sent to AI in that Space. State which actions need a named person’s approval, where the agent should post a proposal, and what evidence to include. Then test that the agent follows them.

Example Space instructions for approvals

You work for the Ops team. You may read from Stripe, HubSpot, and the Ops SOPs folder. Never issue refunds, change subscriptions, or reassign CRM owners yourself. For any of those, post a proposal in #ops-approvals with the record, the change, the reason, and the source data you used. Dana or Marcus approves in the thread, and a person makes the change.

Where do approvals happen in a shared AI workspace?

In type.com, a person approves the setup plan, each connection and its tools, every change to a shared skill, and whether an automation runs. Approval for individual agent actions is a workflow you design in the thread.

Permissions decide what is possible. Approvals decide what happens next. A shared workspace should make the high-impact moments explicit, so nobody discovers a new connection or a changed procedure after the fact.

Space templates only propose skills, automations, and connections. Nothing is added until you approve it during setup. When you ask AI in a conversation to use an app, type.com asks before assigning an available workspace connection. For a custom MCP connection, signing in does not save it: you test the connection and review its tools first.

Shared skills have an owner. Creators can edit their own skills, admins can edit any skill, and other members propose changes as suggestions that a reviewer accepts or denies. Automations follow the same principle. A new automation stays disabled unless you explicitly ask for it to start, and you can run a private test from the editor that only you can see.

For the last row of the table, our guide covers how to prepare a reviewable proposal and verify what happened afterward: How to design AI agent approval workflows

Five approval points in sequence: a setup plan the user approves, a connection the person adding it tests and reviews, skill edits a creator or admin accepts or denies, an automation the user switches on after a private test, and agent actions an authorized reviewer approves.
Four approval points are built into type.com. The fifth, approving an action the agent proposes, is a workflow you design.
Approval points in type.com, from docs.type.com
MomentWhat needs approvalWho decides
Space setupSkills, automations, and connections a template proposesThe person running setup
Connecting a toolAssigning a workspace connection, and testing and reviewing an MCP connection’s toolsThe person adding the connection
Changing a skillA teammate’s suggested edit to a shared skillThe skill’s creator or a workspace admin
Starting an automationSwitching on a new automation after a private testSpace owners and workspace admins, who manage the Space setup
Agent actionsRefunds, CRM updates, and other changes the agent proposesThe reviewer your workflow names

What does read-only actually protect?

Read-only is an instruction to the agent, not a lock on the service. The connected tool’s own account permissions are what actually block a write.

This is the distinction teams most often miss. type.com’s documentation says that read-only tells the agent not to make changes and does not block changes at the connected service. To restrict what the service itself allows, use the service’s own account permissions.

The strongest setup uses three defenses together: an account, role, or key in the source system that can only do what the team needs, a Space assignment that keeps the connection away from teams that do not need it, and instructions that tell the agent which actions require approval.

Plan for partial failures too. If an action fails after it starts, it may still have completed in the connected service. Check the service before you retry, because a retry can repeat the action.

  • Set the real ceiling in the connected tool with a limited account, role, or key.
  • Use Space assignment to keep each connection away from teams that do not need it.
  • Use read-only and Space instructions to tell the agent what not to do, then verify that it follows them.

How do you test permissions before inviting the whole team?

Ask the agent what it can reach from the Space, check the tool calls behind its answer, repeat the request from a teammate’s account, and test every automation privately before you switch it on.

Every thread shows the agent’s tool calls. Open the details to see which connection and tool it used, what input it sent, whether the call succeeded, and what result informed the response. That turns a permission test into evidence instead of a promise.

Illustrative thread: Marcus asks the Ops agent which systems it can reach and whether it can change anything. The agent shows Stripe and HubSpot tool calls, then answers that Stripe is read-only, HubSpot is an organization connection also assigned to Sales, and Gmail is not assigned to the Space.
An access check before rollout. The answer is only as good as the tool calls behind it, so open them. The conversation is fictional.
  1. 1

    Ask for an access inventory

    In the Space, ask the agent to list the systems it can reach and what it can change. Compare the answer with Space settings, then open the tool calls.

  2. 2

    Repeat from a teammate’s account

    Have a member with narrower access ask the same question. A personal connection should only return what that person can see in the source app.

  3. 3

    Try a request that should be refused

    Ask for an action your instructions reserve for approval, such as issuing a refund. The agent should post a proposal instead of acting.

  4. 4

    Run each automation as a private test

    Select Test automation in the editor. It runs in a private thread that only you can see, so you can check the result and the tool calls before the automation goes live.

Copyable access-check prompt

Before we roll this Space out, list every connected system you can reach from here. For each one, say whether it is a personal or organization connection, whether it is marked read-only, and which actions you will not take without approval. Show the tool calls you used to check.

How should you compare AI workspaces on pricing and permissions?

Ask every vendor the same questions: what the price includes, how access is limited by team, whose credentials the AI uses, and which approvals the product enforces. Then ask them to show each answer in the product.

Feature lists blur together, so evaluate with a fixed set of questions. A vendor that cannot show you where a connection is scoped or who approves a change to shared instructions is asking you to trust a slide.

For reference, type.com plans include team members and a shared pool of AI usage. type.com Basic is $50 per month for 2 members and $100 of usage, type.com Pro is $100 per month for 4 members and $200 of usage, and three Enterprise tiers cover 20, 40, or 60 members. Requests that run through a connected Claude or ChatGPT subscription are covered by that subscription instead of the workspace allowance.

See current type.com plans and AI usage pricing

Questions to ask when comparing AI workspaces
QuestionWhy it matterstype.com’s answer
What does the price include?Seat prices can hide usage costs, and usage prices can hide seat minimums.Each plan includes a set number of members and shared AI usage, metered at provider rates.
Can access be limited by team?An ops workspace should not be visible to every employee.Private Spaces, private threads, and per-item sharing.
Whose credentials does the AI use?A shared admin login effectively makes every user an admin.Personal or organization connections, chosen per tool.
Can a connection be limited to one team?A CRM connection for Sales should not appear in every Space.Connections are assigned to specific Spaces.
Who approves changes to shared instructions?An unreviewed edit to a shared skill changes everyone’s results.Members suggest edits, and the creator or an admin accepts or denies them.
Can recurring work be tested first?A bad automation repeats its mistake on a schedule.New automations stay off until switched on, with a private test run.
Are SAML SSO and SCIM available?Larger companies often require them in a security review.Not offered today. Teams with requirements beyond the self-serve plans can ask about a custom contract.

Frequently asked questions

What is a shared AI workspace?

A shared AI workspace is a place where a team works with AI together. Threads, connected tools, reusable skills, and automations belong to the team instead of living in each person’s private chat, so coworkers can read, continue, and review the same work.

How do I give my ops team an AI workspace with team-level access controls?

Create a private Space for the ops team and add only its members. Connect shared systems as organization connections that use an account scoped to the team’s records, assign them only to that Space, and keep tools like email as personal connections. Then write the team’s approval rules into the Space instructions and test them before inviting everyone.

Does a connected tool become available to everyone in the workspace?

No. In type.com, adding a connection to the workspace does not give every Space access to it. Each connection is assigned to the Spaces that need it, and the connected service still applies its own permissions.

Can the AI see private threads or another person’s Sidekick?

A private thread is visible only to its participants, and Sidekick is private to its owner. type.com does not move private Sidekick or private-thread context into workspace memory, and AI acts with the effective access of the person and conversation that started the work.

What is the difference between permissions and approvals?

Permissions decide what a person or the AI can access. Approvals record that a person agreed to a specific change, such as adding a connection, accepting an edit to a shared skill, or carrying out an action the agent proposed. A secure team workspace needs both.

How much does type.com cost for a team?

type.com Basic is $50 per month for 2 team members and $100 of monthly AI usage. type.com Pro is $100 per month for 4 members and $200 of usage, and three Enterprise tiers cover 20, 40, or 60 members. Requests that run through a connected Claude or ChatGPT subscription do not use the workspace allowance. New workspaces start with a 14-day free trial.