Currently you need explicit permissions on a workspace to see private docs for that access group, regardless of whether you are a workspace admin.
We should add a special check to see if the user is a workspace admin, which would then bypass the ws_auth workspace ID check for the user and allow them to see any workspace data.