Collaboration and Administration
Understand shared workspaces, permissions, sharing, settings, and administrative visibility in MARCUS.
MARCUS is built for institutional work. People collaborate inside an organization, use focused projects, and may have different controls depending on their responsibilities and workspace configuration.
Current data boundary: MARCUS is an institutional non-PHI workspace. Invitations, project names, questions, reports, support messages, and shared links must not contain PHI, patient identifiers, patient-specific clinical facts, credentials, secrets, or other prohibited data.
Audience and Availability
This page is for every MARCUS user. Sections about invitations, access changes, project deletion, security settings, analytics, costs, integrations, and billing apply only to people who can see those controls.
MARCUS supports several organization and project roles, but the exact behavior can vary by deployment configuration. The controls visible in your current workspace are the practical guide to what you can do. Do not use this page as a fixed role-permission matrix.
The Collaboration Boundary
Workspace boundaries
Where access and information are separated
MARCUS separates work by signed-in workspace, organization, and project before it uses project information.
Signed-in workspace
The clinician's session establishes identity and available memberships.
Organization
Membership, roles, and organization settings define the next boundary.
Selected project
Project authorization is checked before project data is used.
Project source set
Sources and searchable passages available to the project.
Conversation context
Questions can use the selected project; saved conversations remain organization-scoped.
The main boundaries are:
- Account: identifies the person using MARCUS.
- Session: keeps that person signed in and records the active context.
- Organization: the institutional workspace that contains members and projects.
- Project: the focused working area containing sources, conversations, and knowledge artifacts.
- Collection: an optional source grouping with its own membership and visibility.
- Shared output: a separate copy or link whose audience depends on the sharing method.
Always check the active organization and project before uploading, asking, editing, exporting, or sharing.
Join or Switch an Organization
An account may belong to more than one organization. MARCUS may ask you to select an organization during sign-in, and the application can provide an organization switcher afterward.
After switching:
- Confirm the organization name in the application shell.
- Open the intended project.
- Check that the expected sources and conversations are present.
- Stop if the visible content does not match the workspace you intended to use.
A missing project after a switch may be an access issue, not data loss.
Work With Project Access
Projects keep related sources and work together. Depending on your access, you may be able to:
- view sources and ask questions
- upload, retry, reprocess, or remove sources
- change a project title or settings
- manage project members or invitations
- archive, restore, or permanently delete a project
Archive, restore, source removal, and permanent project deletion can affect other users. Read the confirmation screen carefully and use the narrowest action that solves the problem.
Project membership enforcement can differ by workspace configuration. Do not assume that a project is private simply because it has a member list. Ask your organization administrator which access policy is active if the distinction matters.
Invite and Manage People
Where invitation controls are available:
- Confirm that the person should have access to the organization or project.
- Use the intended institutional identity.
- Select the least access needed for the work.
- Review pending invitations and revoke incorrect or obsolete ones.
- Recheck access when someone changes role or leaves the team.
Invitation delivery, domain restrictions, and single sign-on requirements may depend on your organization's configuration.
Do not place clinical content in an invitation message. An invitation grants access; it is not a secure clinical communication.
Share an Answer
MARCUS can create a read-only public snapshot of an answer. The snapshot can include the question, answer, and citation labels, but it does not give the recipient access to the underlying project documents.
This distinction is important: public means anyone with the link may be able to view the snapshot. The default expiration is typically 30 days, and the creation flow may allow a period from 1 to 365 days.
Before creating or sending a link:
- Read the entire question and answer.
- Confirm that neither contains PHI, patient-specific facts, confidential material, credentials, or secrets.
- Check every citation label for information that should not be disclosed.
- Choose the shortest practical expiration.
- Revoke the link when it is no longer needed.
The share does not prove that the answer is current, complete, or institutionally approved. Recipients cannot use the link to inspect documents they are not authorized to access.
Understand Administrative Visibility
Authorized administrators or program leads may be able to see organization-level usage and question details. Available analytics can include:
- question volume
- active users and sessions
- uploaded source counts
- token use
- estimated operating costs
- activity grouped by user or project
- question-level records for people with the required permission
Do not assume that searches or conversation content are invisible to workspace administrators. Analytics are operational records; they are not a measure of clinical quality, accuracy, educational performance, or individual competence.
Use Settings Safely
Personal settings may include profile, session, response-style, appearance, source-preview, integration, notification, and reduced-motion controls.
Administrative settings may include organization information, user management, security controls, single sign-on settings, integrations, and other workspace policies.
Some visible settings are preparation for features that remain disabled by default. Saving a preference does not prove that the related server-side feature is active. Examples can include personalization profiles, summaries, digests, and suggested questions.
Security and single sign-on screens show configuration options. Their presence alone does not prove that your deployment has completed institutional security review or that single sign-on is active.
Connect External Source Services
Your organization may enable selected-file imports from approved services such as Google Drive, OneDrive, Dropbox, Notion, Box, SharePoint, or a managed network relay.
Connector behavior varies:
- some connectors import only files or pages you select once
- some folder or scheduled-sync capabilities are limited pilots
- institutional sources can require information-technology approval
- access can be revoked or expire
- imported content still follows the same non-PHI workspace boundary
Before connecting a service, confirm the account, folder, site, or page set you are authorizing. Never paste credentials or secret keys into MARCUS content fields or support messages.
Expected Result and How to Verify It
A well-governed workspace should make the current context and the consequence of each collaboration action clear.
Verify that:
- the organization and project names are correct before every content-changing action
- invited people and pending invitations match the intended team
- removed access no longer appears where you can verify it
- shared links have the intended content and expiration
- revoked links no longer open
- administrative reports are interpreted as usage data, not answer-quality evidence
- connector imports list the expected source and project
Common Problems
| What you see | What it may mean | What to do |
|---|---|---|
| A project or control is missing | You are in another organization, lack access, or the feature is disabled | Confirm context, then ask a project owner or administrator |
| An invited person cannot join | The invitation expired, identity differs, domain rules apply, or SSO is required | Review the pending invitation and organization sign-in policy |
| A user can see more projects than expected | The workspace may use organization-wide project access | Ask an administrator to confirm the active project-access policy |
| A share link exposes too much | The question, answer, or labels contained inappropriate material | Revoke it immediately and follow your organization's incident process |
| A shared recipient cannot open a source | Public answer snapshots do not grant project document access | Share the approved source through an authorized institutional system |
| A setting has no visible effect | The related server feature may be disabled | Ask an administrator whether the feature is active |
| An integration is absent | Provider setup, approval, or feature activation may be incomplete | Use manual upload or contact the integration owner |
| Analytics look low or incomplete | Time range, permissions, or collection may differ | Check filters and availability; do not treat missing data as zero |
Safety Checklist
- Use institutional identities and the least access needed.
- Never assume a project, conversation, or shared link is private without checking its actual audience.
- Keep PHI, patient-specific facts, credentials, and secrets out of all MARCUS fields.
- Revoke obsolete invitations, sessions, connector access, and shared links promptly.
- Use approved institutional systems to distribute source documents.
- Escalate unexpected access or disclosure through your organization's security process.
Continue Reading
- Previous: Conversations and Knowledge Tools
- Next: Safe Use and Limitations
- Related: Sharing Answers, Managing Projects, Security Model, and Pages and Routes