Three orthogonal things
Confusing these causes most permission surprises, so they are worth separating.
A paid seat confers no access to anything, since somebody still has to share it with you. But the
reverse is not true either: a viewer seat cannot author, whatever permission it holds. See below.
How access to an object resolves
In order.- Workspace admin? Owner-level access, on dashboards and skills.
- An explicit grant for you? That grant.
- A guest? Nothing further. A guest holds only explicit grants.
- Otherwise, the object’s workspace baseline.
The cap lowers the capability, not the record. A read-only member still owns the dashboards they
own, because attribution and ownership transfer both depend on that staying true.
Defaults differ by object kind
Chats are the exception that matters. A conversation is private, and workspace admins do not get into
yours. Grants on a chat are viewer-only, because there is only ever one writer.
Dashboards defaulting to workspace-readable is an admin setting, under Settings → General → Details.
An admin can make new dashboards private by default instead.
Viewer seats cannot author
This is the part people get wrong, because it looks like a budget limit and is not. A viewer seat is a licence fact, a free licence inside a shared workspace. In that workspace, authoring is refused before any money question is asked. Granting budget does not unlock it, and neither does holding Editor permission on a dashboard.
Granted budget buys metered consumption — asking questions, applying filters, extracting an upload —
never authoring. Seats sell capability; credits buy consumption.
In a personal workspace none of this applies, because you are not on a viewer seat there.
Guests
A guest is somebody invited by email who is not a member of your workspace.- They hold only explicit grants. The workspace baseline never applies to them.
- They are always read-only, whatever a grant says.
- They can see the workspace roster, so they know who they are working with.
- They see only their own account settings, not the workspace’s.
- They get no request-access button, since their access is exactly what was shared with them.