Skip to main content
Each organization has one Owner and can have Admins and Members. A person can hold different roles in different organizations. Open your organization’s team settings in the dashboard to manage access.

Role capabilities

Members are trusted developers with access to shared production credentials and resources. Their API calls can incur charges. This role does not provide read-only access, isolation between resources, or a hard spending limit. Use API-key scopes to restrict individual integration keys.

Invite teammates and change roles

New invitations and SSO/domain joins default to Member. Owners can also invite Admins. An invitation must match the recipient and still be valid when accepted; accepting a new invitation cannot change an existing teammate’s role. Owners manage role changes from team settings. Existing organizations preserve access through the role update: the first existing member becomes Owner, and other existing teammates retain Admin access. Team controls do not allow you to change your own role, remove yourself, or deactivate/reactivate yourself. Another authorized teammate must perform those actions. Personal account deletion has its own eligibility checks.

Deactivate or remove access

Deactivate a teammate when you want to retain their place and role in the roster while blocking access. Deactivation removes dashboard access and revokes delegated credentials and pending invitations. New invitations and domain auto-join cannot silently restore a deactivated membership. An authorized teammate can reactivate the user with their previous role. Previously revoked credentials remain revoked and must be connected again when needed. Removal ends membership and revokes the user’s organization-bound agent/MCP credentials and invitations. Shared organization keys continue to work. Rotate shared keys a departing teammate may have copied to fully remove that API access.

Transfer ownership

The Owner can transfer ownership to an existing active teammate. The recipient becomes Owner and the previous Owner becomes Admin. Transfer ownership before deleting a personal account that owns a shared organization. Organization deletion is an Owner action that requires the organization name for confirmation and an ended subscription. It removes team access, disables organization keys, and revokes integrations. Teammates’ personal accounts remain available.