Managing workspaces

A workspace is a folder of registers plus a bundle of defaults. Manage them from All workspaces.

Creating a workspace

  1. Select Create workspace.
  2. Name it after a risk domain — Operational Risk, ISMS, Third Party — not after a department.
  3. Choose a key and a colour. The key prefixes record IDs and cannot be changed later.
  4. Set the defaults new registers will copy: methodology, layout, baseline access, retention.

Defaults are copied when a register is created, not linked. Changing a default afterwards leaves existing registers untouched — deliberately, so a register’s methodology cannot change under it.

Members

Adding somebody to a workspace makes them visible in it. It does not by itself give them access to registers — that comes from a grant. See Granting access.

Archiving

Archiving makes every register in the workspace read-only. Nothing is deleted, history is kept, and reporting still includes the data. Use it when a risk programme ends but its evidence must survive.

An archived workspace can be restored at any time.

Deleting

Deleting is destructive. You must type the workspace name to confirm. There is a 14-day restore window, after which the data is gone permanently.

If you are deleting because a programme ended, archive instead. Archiving is almost always the right answer, and deletion is almost always regretted at the next audit.

Independence

A workspace can be marked as sealed and assigned to an independence group. Only members of that group can enter it — including the platform administrator, who is otherwise able to reach everything.

Use this for internal audit workpapers. A sealed workspace cannot have baseline access.