API collaboration workspaces · PUBLIC RESEARCH BRIEF
PostmanWhich workspace cue prevents an API artifact from being shared at the wrong boundary?
Postman currently documents internal, partner and public workspaces that can contain APIs, collections, environments, mocks, monitors and other linked elements. Workspace roles affect invitations and collaboration. This brief studies boundary and role comprehension with fictional APIs; it does not claim that a workspace label alone prevents secret exposure or access mistakes.
Updated 2026-10-07 · Simulation results not yet generatedCHANGE ONE THING. LEARN WHAT MATTERS.
Three questions for the GTM team.
When inviting an external collaborator, would a role capability checklist or a sample 'what this person will see' view better prevent overbroad access?
Set up this study →Before publishing a workspace, would a secret-scan result or an element-by-element exposure inventory better help a team decide whether the workspace is ready to become public?
Set up this study →PROPOSED AUDIENCE
Who should weigh in?
North American software, platform and developer-experience teams using or evaluating Postman, including API designers, developers, partner engineers and workspace administrators. Recruit participants with different roles and experience sharing internal, partner and public artifacts. Proposed audience; no production endpoint, credential or customer API is included.
TWO TIME HORIZONS
Trial today. A habit tomorrow?
Near term · 0–90 days
Over 0–90 days, test fictional Postman workspaces containing mock APIs, collections, environments and monitors with seeded dependencies and fake secrets. Measure destination prediction, role comprehension, secret-detection follow-up and unsafe publish attempts. Make no request to a production API.
Longer term · 3–12 months
Over 3–12 months, follow consenting teams in sandbox workspaces as partners, roles and API artifacts change. Examine stale access, duplicate environments, broken monitor handoffs and public-workspace maintenance. Claims about security or delivery speed require separate technical and operational evidence.
What would make the result actionable?
Use versioned Postman documentation, synthetic workspaces with a hidden dependency and access map, fake credentials designed for detection, and task logs. Verify every artifact's destination and role permissions; conduct security, privacy and developer-experience review; never include a live token or customer endpoint.
A Gather simulation returns hypothetical customer reactions. Quantifying revenue, traffic or retention needs actual business inputs and validation against observed behavior.