This is a template. Replace it with wording reviewed for your jurisdiction before you go live.
Workspace isolation
Every record belongs to exactly one workspace, and that scope is enforced in the data layer on every request, not by filtering in the interface. A user cannot reach another workspace’s data by changing a URL.
Access control
Roles are permission trees: each role grants specific actions on specific modules within specific apps. Invitations grant membership of one workspace only.
Accounts
Optional two-factor authentication and per-workspace IP rules, with an audit log of significant changes.