What a workspace is
A workspace is the secure space where a project's data, tools, and people come together. Here is what it is, and how the two kinds differ.
A workspace is an isolated, governed environment for a piece of research. Personal workspaces are private to you; collaborative ones are shared with a project team.
What a workspace is
A workspace is the secure environment where you do your work. It holds the project's datasets, the tools used on them, the people allowed to see them, and the results they produce. Everything stays inside it, and access is mediated by the platform rather than by whoever happens to have a copy.
One workspace, one project. That is the whole idea, and it is what makes the rest of the rules simple to state.
Personal vs collaborative
- Personal - private to you, for your own work.
- Collaborative - shared with a team, for multi-person or multi-centre projects.
They behave the same way. The difference is who is in them.
Workspaces and projects
A collaborative workspace serves a project: its participants, datasets, and permissions are defined by the project's governance. That is what keeps access aligned with the terms the project was approved under - not with who happens to ask.
How workspaces stay separate
Workspaces do not share anything with each other. They are isolated at three levels at once:
- Network - a workspace cannot reach another workspace over the network.
- Storage - each workspace's files are confined to that workspace.
- Running processes - the tools running inside one workspace cannot see or touch those in another.
You only ever see the workspaces you have been given access to. This is what makes it safe to run projects with very different confidentiality requirements side by side on one platform.
What "the unit of isolation" means in practice
The workspace is not just a folder with a label on it. Everything the project uses - its storage, its running tools, its services, its credentials - belongs to that one workspace and lives nowhere else.
Two consequences follow, and both matter to you:
- Nothing leaks sideways. There is no shared scratch space where two projects could meet by accident.
- When the workspace goes, its environment goes with it - completely, and in one step. See Close a workspace for what that does and does not include.
How connected a workspace is
A workspace does not have to be connected to the internet, and by default it is not. Three modes are possible:
- Air-gapped - no outbound network access at all. This is the default, and it is where a workspace starts.
- Restricted - the workspace can reach a defined list of allowed domains, and nothing else.
- Open - normal outbound internet access.
A workspace is sealed unless someone decides otherwise, and each step towards openness needs a reason - a tool that must fetch packages, a reference resource held elsewhere. Convenience is not one.
Whatever the mode, it governs network reachability only. Data entering and leaving the workspace goes through the approval process regardless, and that never happens without a human decision.
Working in it together
Several people on the same project can each open their own session in the same workspace and work at the same time. They share the workspace's storage, so files one person puts there are visible to the others - which is the point of a collaborative workspace, and worth remembering before you write into a shared folder.
Governance and audit
Communication, data transfer, and tool use are all mediated by the platform, and every consequential action is logged and auditable - who did what, and when.