You need account:admin:team to manage invitations and permissions. You can grant only permissions you hold.
Send an invitation
- Open Settings → Team, then Invite member under Pending Invitations.
- Enter Name and Email.
- Select direct Permissions and, optionally, Teams you already belong to. The invitation endpoint rejects teams outside your own memberships, even if the picker lists them. Team members inherit their team’s permissions.
- Click Send invitation.
The recipient follows the invitation link. New users create a password and verify their email; existing users sign in to accept access. Review permissions before granting access to sensitive records.
Manage pending invitations
Pending invitations have a separate section from members, but listing and cancelling them currently require platform access. Workspace administrators may not see outstanding invitations here. Ask a platform administrator to check or cancel a pending invitation when needed. There is no resend button; arrange cancellation before sending a replacement.
Approve a domain access request
During signup, a work-email domain matching an existing organisation offers an access-request route. The requester submits their details and waits for approval instead of creating a duplicate organisation.
The current access-request list, approval and decline operations require a platform administrator. Workspace administrators may see no requests because these operations are unavailable to them; ask your platform administrator to review outstanding requests. For a platform administrator:
- Open Settings → Team → Access Requests.
- Review the requester and email address.
- Choose Approve for this instance, Approve for all active instances, or Decline. Check the scope carefully before approving all.
See Configure organisation settings to set the domain.
Change permissions and teams
On a member’s Manage menu choose Permissions. The dialog distinguishes direct, inherited and denied permissions. Removing an inherited permission for one person records a denial for that person; it does not edit the team for everyone. Removing your own administrator access requires confirmation and another administrator to restore it.
Under Teams, New team opens a name and permissions form, but the current creation endpoint is restricted to platform operators. A workspace administrator can see the form yet receive an access error on submission; ask the platform administrator to create the team. Use an existing team’s Manage button to add members, rename it or change its permissions with account:admin:team. The superadmin system team cannot be renamed or deleted and must retain a member.
See Disable or remove a member when someone leaves.