Account and access
Credits and billing, roles, per-system permissions, and where your data lives.
Credits and billing
Credits pay for Winston's work: 100 credits = $1 on Starter, $0.83 on Pro. Cost varies with the job (request length, data volume, date range), so run a report once and read Settings → Billing → Usage before scheduling it. Usage is tracked per workspace, not per person. Plans: Starter $300/mo = 30,000 credits; Pro $1,000/mo = 120,000. Plans are billed from a linked bank account, so there are no card fees; link one under Settings → Billing → Payment method before you choose a plan. Plan credits reset monthly and purchased credits roll over, but the terms can change, so read Settings → Billing for what applies to your workspace. Auto-recharge is off by default and needs an active plan. At zero, Winston replies with an out-of-credits message and does no work; nothing is charged without a payment method and a chosen plan.
The Earn credits page (click Credits earned, bottom left) lists the setup steps that earn free credits, and you can spend earned credits without an active plan. Expiry terms can change, so check Settings → Billing before you count on a balance being there later.
1- 1Your credit balance and the steps that earn more.
Workspaces and roles
A workspace is one business: its connections, its data, its team, its Library. Three roles, no user cap:
Any member can Approve; Winston assumes everyone you invite is back office. Adding teammates earns credits too, up to five (see the Earn credits page, bottom left); invites go out by email as one-time magic links. The Library and Work Audits are team-wide; chat sessions are visible to you and to Admins or Owners with access, and to anyone you share a session link with.
Permissions and data
Per system: Treez was read-only when this guide was checked, with no API writes; confirm what your connection allows in Settings → Connections. Metrc follows the per-license user key you supply, so a read-only Metrc user's key keeps Winston read-only. Google Workspace, Slack, and the rest grant whatever their connection grants. The unlink icon on any Connections card is the off switch: Disconnect removes Winston's access immediately. Undo: ask Winston to unpublish a web page and it will; treat sent emails and Slack posts as final.
Your data and security
Team rules worth putting in your SOP: decide who clicks Approve; supply Metrc a read-only key unless a workflow needs writes; keep loss-prevention prompts to managers; spot-check one line before approving anything outbound; give schedules with delivery on owner sign-off.