Workspaces & organizations
How Spark separates tenants, teams and access with workspaces and organizations.
Everything in Spark lives inside a workspace, and every workspace belongs to an organization. These two containers set the boundaries for your data, your team, and your access, so they're worth understanding before anything else.
Organizations
An organization is the account-level container, managed by your identity provider (the system your company uses for single sign-on). It's the umbrella that one or more workspaces sit under, and it's where identity and access are anchored: who your people are and how they authenticate.
You rarely work "in" the organization day to day. Think of it as the outer boundary that ties related workspaces together under one identity.
Workspaces
A workspace is the tenant where work actually happens. It holds its own data objects, canvases, tasks, files, workflows, agents, members, and settings. Crucially, a workspace is the unit of isolation: data never crosses from one workspace into another. What you see and do is always scoped to the workspace you're currently in.
Because of that isolation, workspaces are how teams keep separate contexts cleanly apart, for example a production workspace and a sandbox, or two entities that must not share data.
How people belong
People are invited into a workspace as members, and a single person can belong to several workspaces. The workspace switcher at the top of the sidebar is how you move between the ones you have access to; each switch gives you a fresh, isolated context.
Why two levels
The two levels do different jobs. The organization groups related workspaces under one identity and access umbrella. Each workspace stays fully isolated so its data and work can't leak sideways. Together they let a company run many separate contexts without giving up a single, governed way of managing who gets in.
Everything else in these concepts, data, Spaces, canvases, tasks, files, workflows, and agents, exists inside a workspace.