Workspace MCP tools
Always registered. 11 tools, listed with the description the server sends in tools/list.
Membership, roles and per-product access belong to identity. See Roles and permissions.
| Tool | Description |
|---|---|
workspace_create_product_role |
Create a product role. A product role is the company’s own name (“Vendedor”, “Empacador”) for a set of ONE product’s permissions. A member with no roles in a product keeps full member access there, an empty role list makes them read-only, and owners and admins bypass roles entirely. Owner or admin only (403 admin_required). Identity refuses 400 unknown_product, unknown_permission or invalid_name, and 409 role_name_taken. Permission keys come from workspace_product_permissions. |
workspace_credits |
Show the workspace’s credit wallet for the current month: remaining, included (resets monthly), granted (packs, valid 12 months), used and reserved, the period, the mode (record = metered only, enforce = refuses at zero) and the rate card (credits per action; 1 credit = $0.01). Any member may call this. Failed generations are never charged. |
workspace_delete_product_role |
Delete a product role. A product role is the company’s own name (“Vendedor”, “Empacador”) for a set of ONE product’s permissions. A member with no roles in a product keeps full member access there, an empty role list makes them read-only, and owners and admins bypass roles entirely. Members who held it lose its permissions but stay restricted in that product (possibly read-only) — a delete narrows, it never widens. Owner or admin only (403 admin_required). |
workspace_invite |
Invite someone to a Destesi workspace by email. Only an owner or admin may invite; identity answers 403 admin_required for a member. The role may be member or admin — an invite cannot make someone an owner, use workspace_set_role after they join. Optionally pre-set the products they may enter (product_access) and their product roles (product_roles); both apply when they accept. Returns the invitation token. |
workspace_list_notifications |
The signed-in user’s alerts from EVERY Destesi app (Commerce orders, Studio videos, Space mentions, Chat routines…), unread first — exactly what the bell shows in any app. Each row has product_id, kind, severity, title, body, url and read. The user sees only what their role allows in each product. |
workspace_mark_notifications_read |
Mark alerts read for the signed-in user only, in every app at once; the rest of the team keeps their own unread state. Passing no ids marks that user’s whole feed read, which is not undoable — say so before doing it on their behalf. |
workspace_members |
List the people in a Destesi workspace with their workspace role. Roles: owner (everything, including billing), admin (members, invites and every product’s settings) and member (uses the products). Any member may call this. Returns each member’s user_id, email, name and role — the user_id is what workspace_set_role and workspace_set_product_access take. |
workspace_notifications_unread_count |
How many alerts the signed-in user has not read across every Destesi app — their badge number, without pulling the feed. |
workspace_product_permissions |
List the permission catalog each product declares — the keys (orders.manage, receive, …) a product role can grant, with a description of each. A product role is the company’s own name (“Vendedor”, “Empacador”) for a set of ONE product’s permissions. A member with no roles in a product keeps full member access there, an empty role list makes them read-only, and owners and admins bypass roles entirely. Any member may call this. |
workspace_product_roles |
List the product roles defined in a workspace: id, product_id, name and permissions. A product role is the company’s own name (“Vendedor”, “Empacador”) for a set of ONE product’s permissions. A member with no roles in a product keeps full member access there, an empty role list makes them read-only, and owners and admins bypass roles entirely. Any member may call this; members’ assignments are on workspace_members (product_roles). |
workspace_set_member_product_roles |
Set which product roles a member holds in ONE product. A product role is the company’s own name (“Vendedor”, “Empacador”) for a set of ONE product’s permissions. A member with no roles in a product keeps full member access there, an empty role list makes them read-only, and owners and admins bypass roles entirely. Pass roles (role ids of that product; [] = read-only) or unrestricted=true to remove the restriction. Other products are untouched. Owner or admin only (403 admin_required); 400 unknown_role, and 409 owner_must_be_unrestricted for an owner. |
workspace_set_product_access |
Restrict a member to a subset of the suite’s products, or lift the restriction. This is not only the launcher tile: each product api asks identity on every request and answers 403 product_forbidden when the member is not allowed in. Pass products as a comma-separated list of product ids (drive,commerce), or all=true for every product. Only an owner or admin may call this (403 admin_required otherwise); an owner may not be restricted (409 owner_must_be_unrestricted) and an unknown product id is rejected (400 unknown_product) rather than silently locking the member out of everything. |
workspace_set_role |
Change a member’s workspace role. Roles: owner (everything, including billing), admin (members, invites and every product’s settings) and member (uses the products). Only an owner or admin may call this (403 admin_required otherwise), and identity refuses to demote the last owner (409 last_owner). Get the user_id from workspace_members. |
workspace_update_product_role |
Rename a product role or replace its permissions; every member holding it is affected on their next request. A product role is the company’s own name (“Vendedor”, “Empacador”) for a set of ONE product’s permissions. A member with no roles in a product keeps full member access there, an empty role list makes them read-only, and owners and admins bypass roles entirely. Owner or admin only (403 admin_required). Pass name, permissions, or both. |