Workspaces, members and settings
Convo keeps structure to two levels: a workspace holds your team, and it holds your products. A product is one public feedback page. There is nothing else to configure between them.
This page covers who can do what, how products are addressed, and what lives on each of the two settings screens.
Workspaces
A workspace is your team's container. It holds your members and their roles, and it groups every product you collect feedback for.
Each workspace has:
- A name — your team or organization, shown in the app.
- A URL — the first segment of every address in the workspace.
acmeputs your workspace atconvo.randomfact.com/acmeand a product atconvo.randomfact.com/acme/WEB. - An owner — whoever created it, and the only person who can delete it.
- Members, each with a role of
adminormember.
A workspace URL is 5 to 20 characters: lowercase letters, digits and single hyphens, with no leading, trailing or repeated hyphen. A short list of words is reserved for Convo's own pages — app, settings, docs, overview, join, login, api, help, admin, assets — and the create form tells you when you have picked one.
An admin can rename a workspace and move it to a different URL, from Workspace at the top of workspace settings. The name is cosmetic; the URL is not. Moving it releases the old address for anyone else to claim and breaks every existing link at once — each product's public page, every embed snippet, every API and MCP call that names the old slug, and any bookmark your users kept. Convo does not redirect the old URL. So pick a URL you can live with, and treat a move as a migration you tell people about rather than a quick edit.
Ownership is separate from all of this: it is set at creation and cannot be transferred in the app. If the owner leaves, the workspace's one irreversible action goes with them.
Roles
Every member is an admin or a member. The difference is administration, not access to the feedback: both roles see and triage everything in the workspace.
| Capability | Member | Admin |
|---|---|---|
| Read every product, including private ones | Yes | Yes |
| Triage feedback: status, replies, titles, merges, tags | Yes | Yes |
| Write and edit changelog entries | Yes | Yes |
| Create a product | Yes | Yes |
| Rename a product, or change its visibility | Yes | Yes |
| Change a product's logo and accent color | Yes | Yes |
| Mint personal API tokens for their own scripts | Yes | Yes |
| Rename the workspace, or change its URL | No | Yes |
| Create, copy and revoke invite links | No | Yes |
| Change another member's role, or remove a member | No | Yes |
| Add, pause or delete webhooks | No | Yes |
| Delete a product | No | Yes |
| Delete the workspace | Owner only | Owner only |
The owner is an admin who additionally holds the one irreversible action, and nobody else can take it — not even another admin.
Invite links
Admins add people from workspace settings, under Invite links. Choose a role, optionally set an expiry date, and create the invite. The link looks like convo.randomfact.com/join/{workspace-id}/{code}; copy it and send it however you like.
An invite is single-use. The moment someone joins with it, it is spent and stops working — so one link is one person, and sharing it more widely does not accidentally admit a crowd. Revoke an unused link at any time from the same list.
Whoever opens the link signs in with Google, sees which role they are being offered, and accepts. Convo then drops them into the workspace. A link that has already been used, has expired, or has been revoked says so plainly instead of failing quietly.
Removing a member
An admin removes a member from the list in workspace settings; anyone can remove themselves. Access ends immediately.
In the background, Convo also cleans up that person's participation records across every item in the workspace. Anything they wrote — feedback, replies, changelog entries — stays where it is. Removing a member takes away their access, not the record of the work.
Every row in the list shows the member's name, email and avatar, so you can see exactly whose role you are changing or whose access you are ending. Convo copies those details from the account the member signed in with, and refreshes them the next time they open the workspace — so someone an admin added by account id alone, or who joined before Convo kept this, is named as soon as they visit. Until then their row falls back to a shortened account id, and hovering any row shows the full id.
Products
A product is one public feedback page: its own board, its own roadmap, its own changelog, its own numbering.
- Name — what you are collecting feedback about, like "Acme App".
- Key — 3 to 5 uppercase letters, like
WEB. The key is the product's address after the workspace URL, and the prefix on every item number. It is the product's identity in the database, so it cannot be changed later. Choose it with a little care; the name you can edit whenever you like, in product settings.
Add a product from your workspace home with New product.
Item keys
Every piece of feedback gets a key of the form KEY-n — WEB-1, WEB-2 — allocated from a counter on the product and incremented in the same transaction that writes the item. Keys are sequential per product, never reused, and nothing renumbers them. They are what you paste into a ticket, an email, or a conversation with a customer.
Merging a duplicate into another piece of feedback is the one thing that retires a key: the duplicate goes, and its text comes back as a reply on the survivor, attributed to whoever wrote it, along with everyone who was attached to it.
Visibility
A product carries a visibility of public or private, and it is created public: as soon as a product exists, its page is live and anyone with the link can read it and post to it.
Visibility gates the entire public surface. On a private product, non-members cannot read the board, the roadmap, the changelog or any item — they get "not found", so a private product never reveals that it exists. Submissions are refused, the public API tools return nothing, and the embed widget has nothing to post to.
Any member can flip it, either way, from Product at the top of product settings — or over the API with update_product. Going private hides the board; it never deletes anything. Every item, reply and changelog entry stays exactly where it is, members carry on triaging as normal, and making the product public again brings the same board back at the same URL. It is the safe way to take a page offline while you rethink it, or to set a product up in private before you announce it.
Product settings
Open a product's settings from the gear in its header, at /{workspace}/{KEY}/settings. The page is members-only; a non-member is sent back to the product's public page.
It carries five sections, plus a danger zone.
Product. The name, which you can rewrite at any time, and the public/private switch described above. The key is shown but not editable.
Connect to AI. The hosted MCP server address, plus one-click links into Claude's and ChatGPT's connector settings. Two scopes are available: a maker scope that signs in as you and exposes the full triage surface, and a public scope with just the two tools an end user's own assistant needs. The MCP server on Convo's own host is the whole story — there is nothing to install.
API tokens. Personal tokens for your own headless work: scripts, CI, curl. A token is yours, not the workspace's, and its plaintext is shown exactly once when you mint it — only a hash is stored, so a lost token is revoked and replaced rather than recovered. Agents and connectors should use the OAuth flow above instead.
Embed the capture box. A one-line script tag that drops the capture box into your own app, posting to this same product. It is capture only; the full board stays at the public URL. A disclosure underneath gives the raw endpoint for teams who would rather build their own component than take Convo's.
White-label. A logo URL and an accent color for the public page, plus a note about custom domains. See below.
Danger zone (admin) — deleting the product. See below.
Workspace settings
Workspace settings live at /{workspace}/settings. Every member sees the member list; the rest of the page is admin-only.
Workspace (admin) — the workspace name and its URL, each with its own save. Changing the URL moves the whole workspace and sends you to the new address; the warning above is worth reading first.
Members — everyone in the workspace with their role. Admins get a role selector and a remove button on each row but their own.
Invite links (admin) — create, copy and revoke, as described above.
Webhooks (admin) — an https endpoint that Convo POSTs to when something happens, so you can drive your own automation without polling. Pick from three events, all enabled by default:
| Event | Fires when |
|---|---|
item.created |
New feedback arrives |
item.status_changed |
An item's status changes |
item.replied |
Someone replies to an item |
Each endpoint gets a signing secret, generated in your browser and shown before you save so you can paste it into the receiving service in the same sitting. Every request carries the event name in x-convo-event and a timestamped HMAC-SHA256 in x-convo-signature-v1; recompute it with the secret to confirm the request came from Convo and is not a replay. An endpoint can be paused and resumed, or deleted outright — deleting stops deliveries immediately. The whole section is admin-only because the endpoint document holds that secret.
Danger zone (owner) — see below.
White-label
The public page is part of your brand, not Convo's. Branding is deliberately light: two fields per product, in product settings.
- Logo URL — a hosted image, which replaces the product name in the public header.
- Accent color — a hex color that drives the page's highlights.
That is the whole theme system, and keeping it that small is a decision. There is no watermark over your page and no paid tier that removes one.
Custom domains
Custom domains are planned and not built. Every product's page lives at convo.randomfact.com/{workspace}/{KEY} today, and there is no host resolver, domain field or certificate automation behind the scenes. Convo will not ask you to point a CNAME anywhere, and you should not set one up in anticipation.
Deleting things
Deletion in Convo is real deletion, and it cascades.
Deleting a workspace is owner-only, and it is the one action in the danger zone. You confirm by typing the workspace's name. Convo then deletes every product in it, every item under those products, and each item's participants, replies and activity; it removes the members, invites and people records; and it releases the workspace URL so someone else can claim it. None of this can be undone.
Deleting a product is admin-only, and lives in the danger zone at the bottom of product settings. You confirm by typing the product's key — WEB, not its name — and Convo then removes the product, all of its feedback, each item's replies, participants and history, and its changelog, through the same cascade. It cannot be undone, and there is no delete in the API or the MCP tools: an irreversible cascade stays behind that typed confirmation. If what you actually want is to take the page down, make the product private instead — nothing is lost and you can undo it.
A single piece of feedback has no delete button anywhere — not in the app, not over the API. The only way one goes away is by being merged into another, which keeps what was said. Replies cannot be deleted at all, and the activity log is append-only by design.
What Convo records
A short summary of what is written down and who can read it.
- Every mutation is on the record. Each item carries an append-only activity log — what changed, from what to what, who did it, and when. Clients cannot edit or delete an entry; only the deletion cascade removes one, along with the item itself. An action taken by an agent is attributed to the agent.
- People records are never public. The record that carries an end user's email is readable by workspace members and by that person, and by nobody else. A separate public profile — display name and avatar, no email — is what the board reads to render authorship, which is why a public page never touches the private record.
- Emails are visible to members only. Every member of the workspace can see them, at any role. They never appear on the public page and are never shown to other end users.
- Notification history is member-only. Who was mailed about which shipped item is recorded for you, and never exposed publicly.
- Secrets stay with admins. Webhook signing secrets live on admin-only documents, so a plain member's browser never reads one.
Where to go next
If you have not set a workspace up yet, Getting started walks through sign-in, the workspace and the first product. For what your users meet on the other side of all this, read The public page.