CupixWorks 5.0 — this article is still being finished. Screenshots marked to be replaced show the right screens and will be retaken before launch. Taken in a support session, so the top of the screen shows a bar you will not see. Each grey box marks a screenshot still to come.
The two workspace grades
A workspace has two grades: Workspace Admin and Workspace Member. There is no guest at workspace level — guest exists only on a project.
Membership arrives as a consequence, not an assignment
This is the rule that surprises people. Adding someone to a project makes them a member of that project's workspace. Nobody adds them to the workspace; the workspace membership follows from the project assignment.
So a workspace member list can grow without anyone having touched it. If you are wondering why someone appears in a workspace you never invited them to, look at the projects inside it.
It does not work in reverse. Ending someone's project assignment does not end their workspace membership. The assignment is what created the membership once; it is not what the membership is made of, so taking it away leaves them in the workspace until somebody removes them there.
Removing them from the team removes everything below it — their workspace memberships and their project memberships go with it.
Each scope has its own vocabulary, and they do not map onto each other
A team grade is not a workspace grade wearing a different name. IA5-SET-AC-15 is blunt about it: there is no rule that says a team Super Admin equals a workspace Admin, and inventing one would let Save quietly convert an inherited permission into a granted one.
What you see instead, when someone only inherits their access from a higher scope, is a dialog with nothing preselected and a line reading Currently inherits {permission} from {scope}. A blank selection there is not a bug. It is the product declining to guess.