> For the complete documentation index, see [llms.txt](https://help.enterprise.ledger.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.enterprise.ledger.com/help-center-v2/guides/workspace.md).

# Workspace settings

Workspace-level settings on Ledger Enterprise: the Master Administrator quorum, API admin rules, the root Certificate Authority, and external signer keys.

**Role: Administrators.**

**Workspace** holds the settings that apply to the whole Workspace rather than to one Account. It has three tabs: **Governance**, **Certificates**, and **External signers**.

## Governance

### The Master Administrator quorum

**Master Administrators** approve Workspace governance changes. That covers creating Accounts, and managing users, groups, Policies and Whitelists.

The tab shows the current quorum and the Master Administrators it applies to.

**Update quorum** sets how many Master Administrator approvals a Workspace governance Request needs. The change is itself a Request.

> **Note:** You cannot add or remove Master Administrators here. They are managed by activating and revoking Ledger device users. See [**Users**](/help-center-v2/guides/users.md).

> **Important:** A quorum change is paused while an Administrator creation is in flight. The tab says so, and the action is unavailable until that Request resolves.

### API admin rules

**By default an API Administrator has no permissions.** The Rules in this section grant them.

Each Rule defines its own sequential approval steps. A step names the API Administrators who may submit the Request, or the API Administrators who must approve it, and a quorum for each.

| Rule                          | What it grants                                                                                                |
| ----------------------------- | ------------------------------------------------------------------------------------------------------------- |
| Policy-based Account creation | API Administrators in the Rule can create Accounts from an existing Policy, once the Rule's approvals are met |

A Rule that has not been set up shows as **Not configured**, and grants nothing.

> **Note:** An API Administrator can only create an Account from a Policy that already exists. See [**Policies**](/help-center-v2/guides/governance/policies.md).

## Certificates

This tab holds your Workspace's **root Certificate Authority (CA)**.

### Display the root CA

**Display** shows the root CA value and its certificate chain.

> **Warning:** The root CA is sensitive. Share it only where it is needed.

### Enable address verification for API users

An API user has no device on which to check a deposit address. Reviewing the root CA is what lets an API user verify an address against the Workspace instead.

This is a **one-time step**, and it needs a Ledger device:

1. Download the root CA.
2. Review its details on your device. The dialog shows the SHA-256 fingerprint to compare.
3. Complete the review on the device.

Once it completes, the tab shows **Enabled** and confirms the root CA was retrieved from the Workspace HSM. You can review the certificate again at any time.

## External signers

This tab lists the registered **external signer public keys** for an on-premises deployment.

The keys are secp256k1, in either form:

* Compressed: `02` or `03`, followed by 64 hex characters.
* Uncompressed: `04`, followed by 128 hex characters.

**Rotate public keys** replaces the complete set in one governed Request. You cannot change one key on its own.

The Request is rejected if:

* No key is given. At least one is required.
* Two keys in the set are the same.
* The requested set matches the current set.
* A rotation Request is already in progress.

The Request detail shows the previous keys beside the requested keys, so Approvers can compare them.

## Related

* [**Users**](/help-center-v2/guides/users.md)
* [**Policies**](/help-center-v2/guides/governance/policies.md)
* [**How governance works**](/help-center-v2/concepts/how-governance-works.md)
* [**The security model**](/help-center-v2/concepts/the-security-model.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.enterprise.ledger.com/help-center-v2/guides/workspace.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
