Workspaces create separation for compliance operations, but not every Drata resource follows the same sharing model. Some resources are specific to one Workspace. Some can be deliberately linked across selected Workspaces. Some are managed at the Account level.
The table below describes the intended operating model. Product behavior may vary by resource, so use the linked task articles for exact procedures and permissions.
Resource or activity | Typical scope | Cross-Workspace behavior |
Account | Company-level | Represents the top-level Drata environment. |
Workspace | Workspace-level | Defines a distinct operating and audit environment. |
Frameworks | Workspace-level configuration | Enable or manage frameworks for the Workspaces where they apply. |
Controls | Workspace-level rows with optional linking | Link selected controls across Workspaces when they represent the same enterprise control. |
Control information | Linked-control scope | Can be managed across linked controls rather than inherited globally by every Workspace. |
Policies | Workspace/control scope | Can be mapped across relevant linked controls. |
Evidence Library evidence | Evidence/control scope | Can be mapped across relevant controls and linked control groups. |
Miscellaneous or externally collected evidence | Depends on evidence type | Do not assume that all evidence automatically propagates across Workspaces. |
Control test instances | Workspace-level | Test instances remain associated with the individual Workspace where they run. |
Monitoring behavior and results | Workspace-level | Treat monitoring configuration and results as Workspace-specific unless the product explicitly indicates otherwise. |
Connections | Workspace or Account configuration, depending on connection type | Assign or manage connections according to the connection’s supported scope. |
Personnel | Scope depends on the personnel configuration | Use Workspace personnel scoping when the people population must be separated operationally or for access. |
Vendors, assets, and other operational data | Depends on the resource | Verify the resource’s supported scope before assuming it is shared or isolated. |
Events | Workspace-aware where supported | Use the events article for how Workspace context is displayed and filtered. |
Tickets | Depends on the originating workflow | Control- and test-related tickets can carry Workspace context; some risk workflows and automations remain Account-level. |
Dashboard metrics | Workspace-filtered reporting | Use the Dashboard to review readiness and test metrics for the selected Workspace or scope. |
The important rule
Do not assume that linking two controls makes every related object identical across Workspaces.
Linked controls allow selected control information, policies, and Evidence Library evidence to be managed across an intentional set of Workspaces. Test instances, monitoring behavior, permissions, and operational workflows may still remain Workspace-specific.
What customers should expect
A linked control represents the same control concept across the selected Workspaces.
A control can be linked only to the Workspaces that the customer intentionally selects.
Evidence sharing is bounded by the linked control relationship; it is not a global Account-wide inheritance rule.
A test or monitoring result in one Workspace should not be assumed to change the test or monitoring state in another Workspace.
Bulk actions should be performed only within the Workspaces and resources that the user is authorized to manage.
Before creating multiple Workspaces
Ask these questions:
Do the groups require different audit scope or framework coverage?
Should different administrators have different access?
Will the groups use different systems, personnel populations, or evidence sources?
Do they have different control owners or operating cadences?
Is the separation worth the additional administration and potential duplication?
If the same controls apply, should they be linked across the selected Workspaces?
If the answer to most of these questions is no, start with one Workspace.
