Workspace collaboration
Quantura evaluates collaboration access from the current workspace membership on every web and API request. An API key identifies a user; it does not permanently encode a workspace role. Removing a membership therefore removes that key’s access to the workspace on its next request without disabling the collaborator’s personal account or access to other workspaces.Permission presets
The API returns the explicit
permissions array for each membership. Backend checks—not hidden buttons or client state—are authoritative.
Resource-specific CSV access
CSV scope can be configured independently of the role:all— the collaborator may exercise their granted CSV permissions on every CSV in the workspace.selected— only the listed CSV IDs are visible.none— no CSV is visible, even if the role normally includes CSV permissions.
Add a collaborator
The user must already have a Quantura account. Pending email invitations continue to use the website invitation flow; the versioned collaborator endpoint activates an existing account directly.Update or remove access
Viewer API example
A Viewer can combine a personal key’sworkspaces:read and datasets:read scopes with current workspace permissions to read a shared CSV. The same request fails after the owner removes that membership. Viewer access never grants write operations or unrestricted access to unrelated Quantura data.