---
title: "Set a member's role in a workspace (tenant admins only; a workspace admin grant does not manage grants)"
method: PUT
path: "/workspaces/{workspaceId}/grants/{userId}"
tags: ["Workspaces"]
---

# Set a member's role in a workspace (tenant admins only; a workspace admin grant does not manage grants)

`PUT /workspaces/{workspaceId}/grants/{userId}`

Upserts the role. A grant on the default "All data" is stored but never narrows access there:
every member opens the default with their organization role. Grants narrow only in other
workspaces.

## Request body

- WorkspaceGrantPutRequest
  - `role` 'viewer' | 'editor' | 'admin' | 'auditor', required

## Response `200`

Grant

- WorkspaceGrantResponse
  - `data` WorkspaceGrant, required
    - `createdAt` string, date-time, required
    - `email` string
    - `name` string
    - `role` 'viewer' | 'editor' | 'admin' | 'auditor', required
    - `updatedAt` string, date-time, required
    - `userId` string, required

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found
- `409` — WORKSPACE_NOT_BACKFILLED
- `422` — USER_NOT_MEMBER

## Changes

- **2026-10-02** `766c2a40e369` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/greentally/apis/esgai-api/changes/workspaces/:workspaceId/grants/:userId/put.md)

---

[API](https://skmtc.dev/greentally/apis/esgai-api.md) · [All operations](https://skmtc.dev/greentally/apis/esgai-api/llms.txt) · [OpenAPI document](https://skmtc.dev/greentally/apis/esgai-api/revisions/4189686230ca?raw)
