Administer d5s
Establish a workspace, assign roles, connect governed capabilities, and prepare a controlled first rollout.
Administer d5s by separating who may enter the workspace, what context they may access, and what actions their agents may perform. A controlled rollout can begin with one project and one connector rather than configuring the entire organization at once.
1. Establish membership and ownership
Confirm the organization owner and workspace owner before inviting a broader group. Organization ownership carries billing and destructive powers that ordinary workspace administration does not.
An organization Owner or Admin can open Settings, choose the organization in Organization · organization name, and select Workspaces to create or govern its workspaces. The same person can also create one without leaving their current page: the workspace switcher lists the current organization's workspaces first, with a Create workspace plus button in its header for that organization. A single Switch organization row opens the list of other organizations; each is one selection and opens the workspace you last used there, and an organization with no workspace yet offers Create first workspace. The create controls appear only for the organizations you may create in, so the switcher shows the same Owner or Admin gate the Workspaces page applies. Other regions appear at the foot of the menu in a compact Other regions section. Available destinations are navigation links, not organization or membership claims, and ask for a fresh account choice; a destination that is not available yet says Coming soon and has no link. Account and organization administration stay in the sidebar. The selected workspace and its settings sections appear in the page body, so changing workspaces does not duplicate organization controls.
To change the organization display name, select General in that Organization group and edit Organization name. The slug is read-only: saving a new display name updates organization labels throughout d5s without changing existing links, workspace access, billing ownership, or existing audit records. The audit log adds an organization rename event.
To require no-training model routing for every member, select Privacy in the same Organization group and enable Require no-training routes for everyone. The setting applies to interactive and unattended work, including sub-agents and auxiliary model calls. It also removes models marked as training on prompts from the organization's workspaces. Turning the requirement off restores normal organization routing but does not weaken a member who enabled their own setting under Account → Privacy. Both scopes default to normal routing, and every change is audited.
The workspace creator becomes its sole Owner. Add users or groups explicitly, either from the organization's Workspaces page or from that workspace's own Settings → Workspace settings → Members section; organization membership alone does not grant access to workspace content. To hand a workspace to someone else, an organization Owner or Admin uses Workspace settings → General → Danger zone → Transfer workspace ownership, or Manage access on the organization's Workspaces page — the route that stays available when the administrator cannot open the workspace themselves. The new workspace starts with its own projects, model policy, skills, connector credentials, and API keys; secrets and project content are not copied from an existing workspace.
For a non-personal workspace, its Owner or Admin can use Invite people in the workspace sidebar or Members settings. Organization Owners and Admins can send the same workspace-scoped invitation. Choose Member or Admin for that workspace; accepting adds a new collaborator to the organization only as a plain member and preserves an existing organization role. Invite each workspace separately. The personal workspace is private and never accepts invitations; its Invite people control instead opens Create a workspace to invite people, creates the named workspace in your personal organization, and lands on that workspace's Members settings with the invitation form open. For a team that purchases seats upfront, raise the seat count before inviting past the subscription's capacity. If your team uses seats on joining, select Review invite first. An organization Owner or Admin reviews the joining charge and individual seat's monthly price, then selects Authorize seat and invite or, when offered, Reserve free seat and invite. Pending invitations carry no charge. Acceptance adds any needed standard seat after payment or the displayed waiver and opens the invited workspace. Existing team members need no extra seat. Expired terms require a new review and authorization; see Plans and credits for quote and offer deadlines. See Sharing and permissions.
A workspace Owner or Admin can change its display name from Settings → Workspace settings → General → Workspace details. Renaming is an ordinary setting, not a Danger zone action. It updates the name shown in d5s without changing the workspace slug or any existing links. An organization Owner or Admin who does not also have access to that workspace cannot rename it from the organization's Workspaces page.
Delete a workspace safely
Open Settings → Workspace settings → General → Danger zone and select Check readiness. The check names and counts every dependency that still prevents deletion. Follow its Review links and remove those resources through their normal product areas; there is no bulk-delete shortcut in the confirmation dialog.
An explicit workspace Owner or Admin can inspect readiness. Only the workspace Owner can continue: request the short-lived six-digit code sent to their email address, type the exact case-sensitive workspace name, and schedule deletion after every dependency reaches zero. Scheduling starts a 48-hour cooling-off period and notifies the workspace's Owners and Admins. The workspace remains usable during that time, and any explicit workspace Owner or Admin can cancel from the same dialog.
Immediately before deleting, d5s checks readiness again. If a resource or pending provider revocation has appeared, deletion is cancelled and the workspace stays intact. Personal workspaces cannot be deleted. Organization administration alone does not grant access to inspect, schedule, or cancel deletion for a workspace the administrator cannot open.
Once the final check passes, the workspace becomes unavailable. d5s sends a completion email when deletion finishes. Contact support if the email remains absent.
Assign the narrowest current workspace role that lets each person do their job:
| Role | Main access |
|---|---|
| Owner | Full workspace control, including members, settings, capabilities, and deletion. |
| Admin | Manage workspace members, settings, skills, and connectors. |
| Member | Create and use workspace resources. |
| Viewer | Read-only workspace access. |
Use project sharing for access to a particular body of work instead of elevating the person's workspace role.
2. Choose a pilot project
Create one listed project with a clear owner, representative files, and a small group of participants. Decide whether it is available to everyone in the workspace or restricted through explicit people and group grants.
Keep project instructions short and operational: identify the purpose, approved evidence, review expectations, and actions that always require a person.
3. Connect capabilities deliberately
Open Connectors and add only credentials appropriate for general use in this workspace. Prefer an external account with the narrowest useful provider permissions. A connected credential attaches to existing and future projects, chats, automations, dashboards, and agents by default; remove it from each project or agent that should not use it. Conversationally created agents use only their draft-reviewed connections and do not inherit future workspace credentials; see Create your first agent.
After activation, review the controls shown for that credential. Known MCP reads normally allow while writes and unknown actions ask. Newly discovered operations absent from the reviewed inventory ask unless an explicit tool policy applies. API operation controls are not available for every connector, so do not rely on an approval boundary unless the credential displays and enforces it.
4. Prove one workflow
Ask a member to complete the workflow interactively and review its sources, tool activity, approvals, generated files, and usage. Only then turn the pattern into an agent or automation.
For autonomous work, start with a budget or conservative schedule and a clear destination. Keep a named person responsible for reviewing failures and external actions.
5. Review the boundary regularly
When VAT-inclusive euro billing is enabled, subscription Checkout asks the buyer to confirm a full billing address. A business buyer can also provide its legal name and a supported tax ID, and Stripe records corrected billing details for later invoices. Checkout itemises the resulting tax before payment, including supported reverse-charge treatment.
Remove unused project grants, archive credentials that should no longer be activated, and investigate repeated approval or authorization failures. On the Connectors page, select an installed provider to review who set each credential up and when, then reassign or archive credentials that should no longer remain active. Use run history to distinguish an agent execution problem from a connector or external-account permission problem.
Organization Owners and Admins can open Settings, confirm the organization shown in Organization · organization name, and select Usage to review model spend, model usage over time, successful skill loads over time, per-member usage, per-agent usage, and activity. The charts share the selected date range. User stats shows member-attributed spend, tokens, and runs over time; use the member picker to filter both the chart and totals table. User avatars follow the member's current profile. Usage without member attribution remains included in Team totals and Activity but is excluded from User stats.
Agent stats shows only agent-attributed spend, tokens, and runs over time; use the agent picker to filter both the chart and totals table. Agent usage includes nested sub-agent runs and uses the agent's current name and avatar. Deleted agents remain as separate historical rows with a fallback identity. Ordinary chat, other non-agent work, and rows without agent attribution remain included in Team totals but are excluded from Agent stats. User stats and Agent stats are complementary attribution views: one run can be counted under the member who initiated it and the agent that executed it. Use an activity table column menu to sort the complete date-range result or search and filter values in that column. The Member column includes usage without member attribution when it exists.
In Activity, open a billed row to see its usage receipt. When its source is still available, Inspect run opens the run trace with the outcome, charged usage, provider attempts, and the visible durable event timeline through that run's terminal event. Event payloads are collapsed until opened. Open conversation returns to the exact turn. d5s rechecks access to the source conversation and each event when the trace is opened, so a restricted, deleted, or otherwise unavailable source does not expose a trace. The trace states when the exact model input was not captured; it does not reconstruct that input from later conversation state.
Workspace stats splits organization spend, tokens, runs, and agent runtime by the workspace recorded on each usage entry. Use the workspace picker to filter both the chart and totals table. Current workspaces show their current name and slug; entries without current metadata remain as separate historical rows with a generated fallback label. The table totals cover the complete selected date range, while charts are limited to the most recent 366 days and say when that limit applies.
The Usage summary also reports the charged total, purchased-credit balance, and current credit pace-window state. A run can be refused when the organization has no available balance, a pace window is exhausted, or its initiating member has reached an assigned spend limit. The refusal message is the authoritative answer. Organization Owners and Admins manage member spend limits through the organization member API; setting or clearing a limit is recorded in the audit log. Review those controls before enabling unattended work.
Select Billing in the same Organization group to manage what the organization pays for. It is an organization page rather than a workspace one, so it stays reachable for an administrator who cannot open any workspace, and an older workspace Billing link redirects to it. The Plan card names the current plan, its status, its seats and price, and when the period ends; Change plan opens a picker with a Personal and a Team side. Which plans it offers follows the organization's kind, and the plans an organization cannot buy are shown but not selectable. A personal organization selects Set up a team to create a separate team, choosing its region before naming it and reviewing its seats. If the team uses seats on joining, setup starts with 1 standard seat for You, team owner; review the displayed offer and renewal before Continue to payment. A remote choice continues at that region's d5s address before any draft or Stripe session is created. An existing team organization without a Team subscription selects Choose seats and start Team to check out that same organization, even when it has no workspace. An active Pro subscription upgrades to Max in place from that picker. Every other plan change is a card-only Stripe Checkout redirect, and every downgrade or cancellation is handled in the Stripe Billing Portal behind Manage in Stripe on the Payment & invoices card, which also serves card updates and invoice history.
A team organization's Plan card adds standard and premium seat steppers with Apply seat changes. The steppers respect committed capacity, including active members and pending invitations that need purchased seats, and they confirm before applying: an increase is invoiced immediately for the rest of the cycle, and a decrease is scheduled for the end of it with the seats usable until then. A scheduled decrease stays on the card with an Undo scheduled change control. The Usage credits card shows the purchased-credit balance and a Buy credits control that opens a top-up. Top-ups are priced in US dollars for every organization; the card issuer converts. Personal plan prices in euro are shown including VAT at the Netherlands rate once VAT is charged at checkout, and every other price is shown before VAT; in both cases Stripe shows the exact VAT for the organization's country at checkout before payment. The plan and Team dialogs state that the subscription renews monthly until cancelled in Settings → Billing through Manage in Stripe and which terms the checkout checkbox accepts; the top-up dialog states that credits are delivered at once. An eligible consumer subscription shows Withdraw contract for 14 days. The separate confirmation records the statement before ending paid-plan access, processing any refund, and sending a downloadable acknowledgement by email. Emailing hello@d5s.tech remains available. See Plans and credits for the outcome. After paying, Stripe returns to this page and it confirms the plan or the credits once the payment has been processed.
Free organizations can run GPT-5.6 Luna. Other catalog models remain visible but unavailable until the organization moves to a paid plan. A workspace Owner or Admin enables available models from Workspace settings → Models. Model availability depends on the current plan and policy. If an expected model is unavailable, contact d5s before asking members to run the pilot.
New Free workspaces start with GPT-5.6 Luna as their only enabled model and default. New paid workspaces initially enable GPT-5.6 Luna, GPT-5.6 Terra, Gemini 3.7 Flash, Grok 4.5, and DeepSeek V4 Pro. Paid EU cloud workspaces with Bedrock access also start with the production Claude models served through Amazon Bedrock in the EU. Downgrading to Free makes only Luna available, and upgrading later restores the saved paid-plan policy automatically.
Open Workspace settings in the Settings sidebar, confirm the workspace named in that group heading, and select Models from the row across the top of the page. A list of model publishers, such as Anthropic or OpenAI, runs down the left side, and each publisher shows how many of its models are enabled. The most widely used publishers are listed first and the rest follow alphabetically. Select a publisher to list all of its models beside it; on a narrow screen the publishers are a dropdown above the list. Each row shows the full model name, a short description of what the model is for, and where the model runs for your organization: Amazon Bedrock or Azure OpenAI in the EU with an EU flag, Vercel AI Gateway, or No allowed route for a model that cannot be enabled. Models that the organization's current plan cannot use stay visible with disabled switches. The All / Enabled / Disabled filter above the list carries the counts for the whole catalog. Beside that filter, Search models matches model name, publisher, or catalog model identifier across every publisher. Every word you type must match, in any order. When the selected publisher has no match for a search or filter, the list moves to the first publisher that has one. The line below the controls reports how many models the search matched across the whole catalog. The search and the filter apply together. A model you switch off while the Enabled filter is on keeps its row until you choose another publisher or filter, so the switch you just used does not disappear. A publisher's count and its bulk control always describe the whole publisher, not the filtered rows.
Newly cataloged models are labeled NEW for 30 days. Use the current Models page to review availability and reasoning controls. A brand icon identifies the model publisher. A $$$ mark identifies the most expensive models; on Free, Pro, and Team plans the composer asks a member to confirm the first time they pick one. Provider and regional labels distinguish available routes, including Amazon Bedrock and Azure OpenAI in the EU. The available list depends on your organization’s access and region. A model appears once, even when more than one route can serve it. Where your organization has Azure OpenAI in the EU, d5s runs GPT-5.6 Luna, Sol, and Terra there; otherwise it uses the default route, and the Models page names the route in use. Adding an available model does not change the workspace default. Members use d5s credits. The organization's storage region does not by itself guarantee regional model inference; see Security and trust.
Use Enable all or Disable all in the header of a publisher's list to turn that publisher's models on or off in one step; the control is omitted for a publisher with a single model. Set the workspace default from the control in the page header, which lists only enabled models. The default model and the last remaining enabled model cannot be turned off, because either would leave the workspace with no model to run. Disable all always spares the workspace default for the same reason, so a publisher holding the default keeps that one model enabled.
Beside the workspace default, Image model sets the model the agent's image generation tool uses for every agent in the workspace. The list is a short allow-list of image models, not the catalog above; each entry shows a rough cost per image, and the platform default is marked. New workspaces start on the platform default. The choice saves as soon as you pick it and applies to the next run. Members cannot change it, and an agent cannot choose a different image model for a single request.
When OpenAI Codex connection is available on the Models page, a workspace Owner or Admin can connect one ChatGPT subscription through OpenAI's device login. Open the secure OpenAI page, enter the one-time code, and sign in with an account your organization authorizes for shared workspace use. d5s stores the resulting refreshable credential for the workspace and never shows it to members. Enable the verified Codex models and choose the Codex workspace default there. Every member then inherits that connection and default for new work, while only workspace Owners and Admins can reconnect, refresh, reconfigure, or disconnect it. Existing named agents that explicitly pin a catalog model keep that pin; choose Workspace default in the agent's Profile to restore inheritance.
Reconnect when OpenAI revokes the login or the ChatGPT subscription changes. Disconnect when the workspace should no longer use that subscription. The organization must allow personal subscriptions, and OpenAI usage remains attributed to the connected account and subject to that account's plan, limits, and terms. If the connection is disconnected, is no longer available to the workspace, or a run requires no-training routing, newly admitted work uses the workspace catalog-model policy instead; already-started work may finish with the runtime it was given. Availability shown on the page is authoritative and can come from the workspace plan or an explicit workspace entitlement, so entitled Free members can use the shared connection without upgrading their individual d5s account; that entitlement changes only the d5s access gate.
Continue with Sharing and permissions, Connect and activate a connector, and Security and trust.