Overview of workspaces

Workspaces in IBM watsonx Orchestrate provide structured areas for developing and managing AI agents, tools, and knowledge bases. Whether you work independently or as part of a team, workspaces help you organize your development tasks with clear access and ownership.

Important: Workspaces are currently supported only on IBM Cloud.

Understanding workspaces

Workspaces are collaborative development areas that help you organize and manage assets during agent development. They act as your development folders, helping you keep your work organized and ensuring that only the right people can see or edit in-progress content.

Workspaces help you:

  • Create artifacts accessible only to workspace members

  • Invite specific collaborators to workspaces and agents

  • Leverage the same watsonx Orchestrate tenant across different teams working on different use cases

Key benefits:

  • Only workspace members can view or modify assets

  • All related assets stay grouped together

  • Workspace owners decide who can join

How workspaces work

Workspaces define who can access and work on assets during agent development.

When you create an agent in a workspace, workspace roles and permissions control access to that agent and its resources. After deployment, the agent becomes available to users across the tenant in Orchestrate Chat. However, workspace membership continues to control access to the workspace and its development artifacts.

Types of workspaces

watsonx Orchestrate provides two workspace types to support different collaboration models.

Use the Global workspace for shared, reusable assets across teams, and private workspaces for project-specific or restricted development.

Table 1. Workspace types and uses

Workspace type

Details

Global workspace

The Global workspace is a shared space available to all builders:

  • Automatically available to every builder
  • Cannot be deleted
  • Does not allow member removal
  • All artifacts created here are visible to all builders
  • Ideal for shared or reusable resources

The Global workspace serves as a common area where all builders can access and share resources across the organization.

Private workspaces

Private workspaces support controlled, project-specific development:

  • Any builder or admin can create them
  • Workspace owners can add or remove members
  • Only members can view or edit assets
  • Suitable for project teams, prototypes, and sensitive work

Private workspaces enable teams to develop agents and manage resources without affecting the broader organization until they choose to deploy.

Understanding workspace roles and permissions

The following summarizes what each service instance role can do across workspaces, including workspace creation rights, default access levels, and eligibility for role elevation.

Table 2. Role summary
Service instance role Can create workspaces Default access across workspaces Eligible for elevation in a specific workspace Effective scope
Admin Yes Admin Not applicable (already highest privilege) Full admin rights in all workspaces
Builder or Writer Yes Editor Yes; can be elevated to Owner in a specific workspace Elevated role applies only to that workspace; Editor everywhere else
WO User No No default access Yes; can be assigned Editor or Owner in a specific workspace Access limited to assigned workspaces

These roles determine how users interact with workspaces and their assets during development.