WorkOS by Befocusy WorkOS Help center

Per-person permissions and separation between companies

WorkOS applies permissions at two levels: between companies and, within each company, between people.

Each company is a separate space

Each WorkOS account has its own connection to its Notion, its own databases and its own settings. When you sign in, WorkOS records in your session which company you belong to, and every action happens inside that space.

On top of that, every time you open or change an item (a task, a document, a contact), WorkOS checks that it really belongs to one of your company's databases. So even if someone knew the internal identifier of another company's item, they couldn't open it from their own.

If you work in several companies with the same email, you switch from one to another from the user menu, and each one keeps its data separate.

Roles within your company

Each person has a role (Owner, Supervisor, Member), and can also be a Technical contact. The role decides what they see and what they can change:

  • Owner: also sees other people's items in the From others tabs and manages the team.
  • Supervisor: sees (without being able to edit) the tasks and documents of their direct reports.
  • Member: sees what's assigned to them and what they take part in.
  • Technical contact: manages the connection with the Notion databases. Being the Owner isn't enough for that.

The details for each section are in the article “Who sees what: owners, participants and Team privacy”.

The most private: email and conversations with Kairos

  • Email is personal. Each person only sees the email from the accounts they connected themselves or that were assigned to them. Not even the Owner sees other people's email.
  • Conversations with Kairos are private too. Nobody else in your company can open them, not even the Owner.

Platform support

To solve setup issues, the WorkOS team can enter your account in preview mode. That mode is read-only: they can check how your account looks, but can't create, change or delete anything (tasks, notes, documents, contacts, settings…). They also can't read anyone's email, see conversations with Kairos, or ask Kairos for anything on behalf of your team.

The WorkOS team signs in to its administration tools only with individual, authorized Google accounts, protected by Google (including its two-step verification). There are no shared passwords, and removing someone takes away their access immediately.

If someone leaves the company

Deactivate their user from Settings → Team. From that moment on they can't sign in again, and their remembered devices and their Kairos connections with Claude or ChatGPT stop working. If they had email accounts connected, disconnect them from Settings → Integrations.