# Set up your workspace

> Get your org ready as its first admin. Add a model key, invite people, set the org-wide settings, and make the one decision that matters.

This page is for the first admin in your org. When you finish, your agents can run, the people who need Mindset can sign in, and someone has chosen how new write operations get approved. It takes about ten minutes.

## What this is

Your company is an **org**. It holds your members, agents, functions, connections, runs, and everything else you build. One org can never see into another.

Inside your org are [environments](https://docs4.mindset.ai/docs/ams/environments), named partitions such as Sandbox, Test, and Production. Your org starts with one, called Sandbox, which is where the invoice exceptions agent will live unless you create another.

Every member has one of two roles:

| Role | What they get |
|---|---|
| **Admin** | AMS: building agents, connections, and functions, and the **Settings** page. |
| **User** | The Hub, where they use the agents published to them. |

People sign in with a Google account or with an email address and password. Microsoft sign-in isn't available.

Your org's **region** is fixed when the org is created. Each region is a separate database, so where your data sits follows from where your org was created. You can see the region on **Settings → Governance**, but you can't change it.

## How to do it

1. **Sign in.** Mindset creates your org and invites you as its first admin.
2. **Settings → Model keys.** If you see "Your organization needs a model key", add the key for the model provider your agents use. Agents can't run until at least one provider key is set. You can add others later.
3. **Settings → Members.** Choose **Invite a user**, enter their email address, and pick **Admin** or **User**. They get an email with a single-use link that signs them in.
4. **Settings → Members**, same tab. Decide whether to turn on **Auto-group new sign-ins**. When it's on, a new person whose email domain matches one of your admins' domains joins your org automatically, as a user. Free email domains never qualify.
5. **Settings → Systems.** Decide whether new write operations need a person's approval. See [The one decision worth making deliberately](#the-one-decision-worth-making-deliberately).
6. **Settings → Governance.** Set what happens to personal data before it reaches the model provider, and how many months audit records are kept (six at minimum).

![Settings → Governance, the personal data policy dropdown: off, redact permanently, redact with audited access, or redact in transit only.](https://docs4.mindset.ai/images/docs/getting-started/workspace-governance.png)

7. **Settings → Defaults.** Pick the reply language your agents are instructed to use, and decide whether members may build personal agents.
8. **Settings → Environments.** Create a second environment if you want somewhere to build that doesn't touch real systems. See [Environments](https://docs4.mindset.ai/docs/ams/environments).

## Settings, tab by tab

Only admins can open **Settings**.

| Tab | What's there |
|---|---|
| **Members** | Invite, remove, disable, and re-enable people, change their role, and send a password reset link. The **Auto-group new sign-ins** switch. |
| **Environments** | Create an environment and rename one. |
| **Governance** | Personal data policy and the patterns it looks for. Audit retention and your data residency region. OpenTelemetry export. Conversation retention, and erasing conversations. Keys for the built-in agents. |
| **Defaults** | Agent reply language. **Allow personal agents**. |
| **Model keys** | Your org's own keys for model providers. |
| **Embedding keys** | The key Mindset uses to embed text for knowledge search. |
| **API keys** | Keys your own software uses to call Mindset. |
| **Systems** | Details for connecting Claude and other MCP clients, and the switch for write operations. |

Switches take effect the moment you flip them. Fields with a **Save** button take effect when you save. Either way, the change applies to everyone at once and isn't versioned.

## The one decision worth making deliberately

The switch is **Turn on connections that change other systems automatically**, on **Settings → Systems**. It's on by default.

A write operation is one that changes another system, such as the invoice agent's "send supplier query". This switch decides what happens when someone adds a new one:

| Setting | What happens when someone adds "send supplier query" |
|---|---|
| **On** (default) | The operation can be called straight away. The record names this setting and the admin who chose it. |
| **Off** | The operation waits until a person approves it, once, on the connection's **Operations** tab. |

In both cases approval happens once, for the operation. After that, every call to it runs. No individual supplier query waits for a person. If the finance lead must read each query before it goes, build that into a [script](https://docs4.mindset.ai/docs/ams/write-a-script) as an ask phase.

The setting covers the whole org, in every environment. It decides what happens to write operations added after you change it. An operation that's already enabled stays enabled until someone revokes it.

An agent can never approve an operation, whichever way the switch is set.

## Things to be aware of

- **Membership is access to every environment.** You can't invite someone into Test only.
- **Personal agents are off by default.** When they're on, a member can build an agent for themselves. It can only hand work to agents already published to that member, so it opens no new access. Turning the setting off stops every personal agent from running. Nothing is deleted.
- **An API key works in one environment**, the one it was created in. The key is shown once, when you create it, so store it in your secret manager before you close the dialog. Give each key one named owner who knows what uses it.

## When it doesn't work

**A colleague signs in and sees almost nothing.** Check their role. A user sees the Hub and only the agents published to them. If they're an admin, check the **Environment** switcher in the left navigation. They may be in a different environment.

**Someone can't sign in with their Microsoft work account.** Microsoft sign-in isn't available. They need a Google account or email and password, on the same address you invited.

**A write operation started working without anyone approving it.** That's the default. Turn off the switch on **Settings → Systems** so new write operations wait for approval, and revoke any existing operation you want held.

## You're done when

- Agents can run, because a model key is set.
- Everyone who needs Mindset can sign in, with the right role.
- Someone has decided whether new write operations need approval, instead of keeping the default without reading it.
- Each API key you've issued has one named owner.
