Understand access
Separate identity, workspace membership and product permissions.
A person signs in to establish identity. A workspace membership determines where they belong. App permissions determine what they can do there. The product still checks whether the specific record is theirs to access.
Use a read-only role when someone needs to inspect results. Grant run/write permissions only when they need to create work. Administrative access is separate from scientific access.
A shared Brain interface does not require a shared database or shared credentials. Each product can keep its own repository and service while using the platform for access decisions.
During the DimerIQ pilot, some older catalogs are workspace-wide. Its isolated data service is restricted to one approved organization/workspace. General multi-workspace support must not be claimed until the relevant storage migration and isolation tests pass.
