Org admins manage users across workspaces from the org console: one identity, per-workspace roles, centralized SSO/SCIM, and a cross-workspace access review. One person, one account, many hats.
The org console
Above workspaces sits the org: shared SSO/SCIM config, the full user directory, and per-user workspace membership with per-workspace roles. Add a user to three workspaces with three different roles from one screen.
Identity model
One login per human across all workspaces. Switching workspaces switches context (role, scope, data) without re-auth. API keys remain workspace-bound — cross-workspace automation needs a key per workspace by design.
Access reviews
The org console's access report lists every user's workspace memberships and roles — export quarterly for access-review compliance. Stale cross-workspace access is the most common finding; revoke from the same screen.
Billing note
Seats can pool at the org level or bill per workspace depending on contract. The org console's usage view shows seat consumption per workspace either way.