Permissions, standards, branding - set once, effective everywhere.
User groups, roles, corporate identity and tenant settings form your organization's control center. Set up once, every new project automatically inherits standards, permissions and branding - traceable down to the change history, instead of permissions in spreadsheets and scattered menus.
Four modules, one control center
Each module solves its own administrative problem - together they keep your organization consistent and traceable. Every card leads to the full detail page.
From empty tenant to a fully configured organization
Four steps, one console: every setting takes effect immediately for the whole organization - and stays traceable.
Standards set
Define numbering schemes, working hours, modules and approval workflows once - every new project inherits them automatically.
Go to tenant settingsPermissions defined
The permission matrix governs in four levels who sees and changes what - globally and per project.
Go to the permission matrixTeams staffed
User groups bring entire teams including their project role into your projects - in one step instead of thirty.
Go to user groupsBrand rolled out
Logo and colors apply from the login screen to the last system email - no CSS, no design team.
Go to corporate designSign-in and evidence hang off the same control center, too: single sign-on via OIDC or SAML, automatic provisioning via SCIM 2.0 or LDAP synchronization - and the audit trail records system-wide who changed what, and when.
The right entry point for every role
IT, management and business units work on the same control center - each role with its own view.
IT administration & IT leadership
Connect your directory, govern permissions centrally, enable modules selectively - SSO via OIDC or SAML, provisioning via SCIM 2.0 or LDAP, all self-service.
Management & compliance
Conclude data processing agreements with legal certainty, evidence every permission change, keep data sovereignty - without having to ask the vendor.
PMO & business units
Staff projects in seconds, rely on uniform standards and work in an environment that looks like your company.
Frequently asked questions about administration with WORKSPACE.PM
The answers to the questions that matter most before rollout.
Both. WORKSPACE.PM ships with protected base roles that cannot be deleted by accident - alongside them, you create any number of custom global and project roles. Every role governs 38 functional areas in four levels from none to administration, and every change is logged with actor and timestamp.
Your choice. Invitations with role escalation protection are enough to get started: nobody can grant a higher role than their own. For your directory there is single sign-on via OIDC or SAML plus automatic provisioning via SCIM 2.0 or LDAP synchronization - secured by DNS-verified company domains, with a log of every sync run.
You conclude the data processing agreement under Art. 28 GDPR right inside the application - as an immutable document with version history. Data sovereignty stays with you: an allowlist governs who may contact support, and you can delete your organization including all its data yourself, irrevocably, at any time.
Yes, on three levels: the system-wide audit trail logs every action with date, user and full-text search. Every role keeps its own change history, and every user account an activity log of all administrative interventions - compliance evidence as a by-product.
Little - that is the concept. You set standards, permissions and branding once; after that, every new project inherits them automatically. You maintain groups in one place and staff the whole portfolio with them, corporate design needs neither CSS nor a design team, and factory defaults take you back to the starting point at any time.
Bring permissions, standards and branding into one place - free for 30 days
All four modules, full functional depth, no credit card. Create your tenant, review roles, upload your logo - ready in minutes.
