Workspaces and members
A workspace owns projects, provider credentials and spend. Members hold one of three roles. Only admins and owners manage credentials, members and settings. Only admins delete projects. Ownership moves through a dedicated transfer, so a workspace can never end up with two owners or none.
An API key belongs to a user, not to a workspace, and carries that user's authority in every workspace they belong to.