admin
Team, Roles, and Departments
Invite users and manage least-privilege workspace access.
Reviewed 2026-06-21Product 1.1
Access model
Effective access combines the user’s base role, access-role permissions, direct allow/deny overrides, department, active status, plan features, and subscription state.
Recommended workflow
- Create departments that reflect operational ownership.
- Create reusable access roles for engineers, analysts, policy owners, and billing owners.
- Invite a user with the appropriate role and department.
- Use direct overrides only for exceptional cases; they are harder to audit at scale.
- Disable accounts promptly when access is no longer required.
Invitation lifecycle
Invitations can be pending, accepted, revoked, or expired. Pending invitations can be resent or revoked. Users cannot sign in until invitation acceptance and password setup are complete.
Review Permissions and features before creating roles.