Team members and roles
Manage people from Team members. Inviting and removing requires the owner or admin role.
Inviting
Section titled “Inviting”Enter one or more email addresses and choose a role for the batch. Each invitee gets an emailed link.
- Invitations expire after 7 days. An expired invitation can be resent, which extends it.
- The invitee signs in — or signs up, if they don’t have an account — and accepts.
- You can cancel a pending invitation at any time before it is accepted.
Pending invitations occupy a seat against any member limit on the workspace, so cancel ones you no longer intend to be accepted.
Three roles. Choose the least privileged that lets someone do their job.
| Role | For |
|---|---|
| Owner | The person ultimately responsible. Exactly one per workspace. |
| Admin | Day-to-day administration — people, settings, keys. |
| Member | Builders. Can use models and manage their own API keys. |
Permission matrix
Section titled “Permission matrix”| Permission | Owner | Admin | Member |
|---|---|---|---|
| View workspace | ✓ | ✓ | ✓ |
| Update workspace | ✓ | ✓ | |
| Delete workspace | ✓ | ||
| View members | ✓ | ✓ | ✓ |
| Invite members | ✓ | ✓ | |
| Update member roles | ✓ | ✓ | |
| Remove members | ✓ | ✓ | |
| View billing | ✓ | ✓ | ✓ |
| Update billing | ✓ | ||
| Manage payment method | ✓ | ||
| View invoices | ✓ | ✓ | |
| Use the playground | ✓ | ✓ | ✓ |
| View settings | ✓ | ✓ | ✓ |
| Update settings | ✓ | ✓ | |
| View audit logs | ✓ | ✓ | |
| View API keys | ✓ | ✓ | ✓ |
| Manage API keys | ✓ | ✓ | ✓ |
| Manage all API keys | ✓ | ✓ |
Worth noting:
- Members manage only their own keys. A member can create and revoke keys they created, but cannot see or touch another member’s. Owners and admins can manage all of them.
- Everyone can see the member list. This is intended, not a leak.
Changing roles
Section titled “Changing roles”Owners and admins can change any member’s role, with two exceptions: the owner’s role cannot be changed, and nobody can be promoted to owner. Ownership transfer is not currently self-serve — contact us if an owner is leaving.
Removing someone
Section titled “Removing someone”This is also why keys should be named after the application that uses them rather than the person who made them — it makes the blast radius obvious before you click remove.
Access to your own account
Section titled “Access to your own account”Personal security settings — password, multi-factor authentication, passkeys and sessions — are at Security and are available to every user regardless of role. See Account security.