Inviting someone
An invitation asks two questions: where the person should have access, and as what. You can grant access at three levels, and combine several in one invitation:- Organization — every account you have now, and every account created later.
- Group — every account in an account group, including accounts added to it later.
- Specific accounts — the accounts you pick, and only those.
What a member can actually reach
Open a member to see their effective access: one row per account, showing the role they hold there and where that role comes from. Access granted through a group is expandable, so you can tell a direct grant from an inherited one. This matters when someone holds more than one grant. A person with an organization-wide role and a different role on one group appears in the roster with Mixed roles, and the member page is where you see what that resolves to account by account. Members whose access comes from an organization-wide role are labelled (organization) in the roster, because they are not attached to any single account.Managing a member
From a member’s row you can edit their role or remove their access. Some actions are not available for organization-wide grants, since those are not held on an individual account.Related docs
- Roles: what each role can do, and how to build a custom one.
- Account groups: granting access to many accounts at once.