Teams, Roles, and Workspaces in xSpeed Hub
An xSpeed Hub account is a workspace that several people can share, each with different powers. Agencies can give a client read-only visibility, contractors access to exactly one site, and teammates full operational control, without sharing a login.
Workspaces
Every person gets a personal workspace on first sign-in. You can create more, name them, switch between them from the sidebar, and delete the ones you no longer need. Sites, members, and connections all belong to a workspace, so “the agency’s fleet” and “my personal sites” stay cleanly separated.
Roles
Members are invited by email as one of three roles:
| Role | What they can do |
|---|---|
| Owner | Everything, including billing, team management, and deleting the workspace. |
| Admin | Everything operational: manage sites, change settings, mint AI connections, but not billing or team management. |
| Viewer | Read-only: sees the fleet, reports, and activity, but cannot change settings, mint tokens, or write through an AI client. |
Roles are enforced on every route and on the AI surface. Permissions are checked at use time, so demoting someone takes effect on their very next call, including calls made with an AI credential they minted earlier. No re-mint needed.
Per-site access
By default, every member sees every site at their own role. To restrict a site to specific members, the “this contractor only touches one client” case. Add a grant on that site. A site with no grants stays open to the whole workspace; adding the first grant is what restricts it.
A site a member cannot see behaves as if it does not exist (a 404, never a 403), so restricted members cannot even enumerate what else is in the workspace.
Invitations
Invitations go out by email and expire in 7 days. The Members section shows people, roles, and pending invites, and lets Owners change roles or remove members.
Safety rails
- Every destructive action asks for confirmation; removing a site or deleting a workspace asks you to type its name.
- Deleting your account requires a 6-digit code emailed to you.
- Your profile page lists your signed-in devices and lets you sign the others out.