A workspace is meant to be shared. Invite colleagues under Settings → Account → Members.
Click Invite Members. Enter an email address and pick a role. Add another one puts more people in the same dialog. Confirm with Send Invites.
The recipient gets a message with a link. If they do not have an account yet, they create one first and then land on the join screen with a Join Team button.
An invitation is valid for seven days. After that the link says so. Under Pending Invites you can see who has not accepted yet, and resend, renew or delete an invitation.
There are two roles you can hand out.
Owner can set everything up: change roles, invite and remove members, deal with billing, change the workspace settings and configure the CRM.
Member does the day-to-day work. A member can invite people and change their own settings, but does not touch the CRM configuration or the billing.
One person is the Primary Owner, the one who created the workspace. Only they can delete the workspace or transfer ownership, and the latter is done with Transfer Ownership in the danger zone.
Beside those two there is a Provider role. It belongs to a party that supplies Ascensie to you and helps you run it. You cannot hand that role out and it does not show up in your member list.
While inviting, Restrict access lets you switch off modules this person does not need. What is off disappears from their menu; the rest of the team notices nothing.
You can change it later too. Open the row of a member in the list and choose Modules.
The same list holds Change Role and Remove from Account. Somebody you remove loses access immediately and has to be invited again to come back.
To leave a workspace that is not yours, use Leave Team at the bottom of that workspace's settings.