Tensic guides

Guide 05

Teams, project access and API keys

How teams scope access in Tensic, what the three permission levels can do, how to share a project with your team or invite one person, and how to create scoped, read-only or expiring project API keys.

On this page
  1. Understand teams and the three permission levels in Tensic
  2. Share a project with the whole team
  3. Invite one person to a project as a normal user
  4. Create a scoped project API key
  5. Privacy by design in user and project access

In Tensic, the team is the access-control boundary. Every project belongs to one team, and it uses that team's models and budget. Inside a project, the Access tab controls who can see the project and which API keys can call it.

Understand teams and the three permission levels in Tensic

Tensic has three permission levels:

  • Platform admin: sees and manages every team on the instance.
  • Team admin: sees and manages only the teams they are admin of. A team admin sees all members of those teams.
  • Normal user: works in the projects they own or have access to. A normal user can't see the team's user list.

How teams work:

  • Everything is scoped to a team. Project sharing, invitations and budgets all work inside a single team. Nothing can be shared between teams.
  • A project follows its team's rules. It only has access to the models the team has, and its usage is billed to the team's budget.
  • Users can belong to several teams, and a user can be team admin of several teams. This covers people who work across departments, for example an engineer who is on both a data team and a project team.
  • Cross-team work: to have people from different teams work on the same projects, create a team that includes all of them. You can't invite someone from another team into a project.

Tensic deliberately keeps a fixed three-level model instead of an unlimited hierarchy. This keeps permissions easy to reason about while still fitting most org structures, including large organisations with thousands of users.

Share a project with the whole team

Sharing makes a project available to every member of the project's team.

  1. Open the project and go to the Access tab.
  2. In the Access section, turn on Shared. The help text reads: "When enabled, all members of the project's team can access this project."
  3. Click Save. A confirmation (Access saved.) appears.

Team members now find the project in their projects library. Sharing only reaches the project's own team, never the whole platform or other teams.

The same section also has a Team field. Changing it moves the project to another team. From then on, the project follows that team's rules and uses that team's budget.

Access section with the Shared toggle, Team field and Invite user form

Invite one person to a project as a normal user

To give one person access without sharing the project with the whole team, send an invitation. This is also the only way for a normal user (not a team admin or platform admin) to add someone to a project, because normal users can't see the team's user list.

  1. Open the project and go to the Access tab. Leave Shared off.
  2. Under Invite user, type the person's username in Username.
  3. Click Send invite.

What happens next:

  • Tensic doesn't tell you whether the user exists or whether the invitation arrived. This is intentional: it stops anyone from using invitations to find out who is on the platform.
  • If the user exists and is a member of the project's team, they get the invitation. People outside the team can't be invited.
  • The invited user sees a notification symbol. They open their avatar menu, go to Invitations and accept or decline.
  • Once they accept, they appear under Users in the project's Access section. The label reads: "Direct assignments — bypasses team membership."

Team admins and platform admins can also add users to a project directly.

Create a scoped project API key

API keys belong to one project. A scoped key can only reach that project's endpoints, and its usage is billed to the project's team.

  1. Open the project and go to the Access tab.
  2. Under API keys, click Create key.
  3. In New project API key, fill in:
    • Description (optional): a note so you can recognise the key later.
    • Expiry: when the key stops working. Choose Never expires or an expiry date. An expired key stops authenticating, and requests with it get a 401 until you create a new key.
    • Read-only key: turn this on for keys that only need to use the project. Read-only keys can read data and run inference (chat, question, embeddings search, /projects/{id}/v1). They can't create, update or delete anything, so they can't change project settings.
  4. Click Create. Copy the key right away. The full key is only shown once.

The key list shows each key's Description, Key prefix, Access, Monthly quota, Expiry, Last accessed and Created date. To revoke a key, click the delete icon under Actions.

Keys are owned by the user who created them. The list only shows your own keys for the project.

When you create a widget, Tensic makes its own read-only key for that one project, so you don't need to create one by hand.

New project API key dialog with description, expiry and read-only options

Privacy by design in user and project access

A few access rules exist mainly to protect personal data:

  • No user enumeration. Invitations never confirm whether a username exists, so no one can use them to guess who is on the platform.
  • Normal users can't see team member lists. Only team admins (for their own teams) and platform admins can.
  • No cross-team sharing. Data and budgets in one team can't be exposed to another team through a project share or invitation.
  • Least-privilege keys. Use read-only keys with an expiry date for apps that only need to call the project.

For logs, redaction and log retention, see Budgets, limits and logs.

Common questions

Can I invite someone from another team to my project?

No. Invitations and sharing only work inside the project's team. Instead, create a team that includes everyone who needs access. Users can belong to several teams.

I sent an invite but got no confirmation. Did it work?

Tensic never confirms whether a user exists. If the username is correct and the person is in the project's team, they'll see the invitation under Invitations in their avatar menu.

What is the difference between Shared and inviting a user?

Shared gives every member of the project's team access. An invitation gives access to one person only.

Who pays for usage of an API key?

The project's team. Keys are scoped to one project, and their usage counts against that project's budget and its team.

What can a read-only key do?

It can chat, ask questions, run embeddings search and call the project's inference endpoint. It can't create, update or delete anything.

Why can't I see a key my colleague created?

Keys are owned by the user who created them. The list only shows your own keys.

What happens if I move a project to another team?

The project then follows the new team's rules: its models, its access and its budget.