Manage members and invitations

Invite workspace users by email, set and change their role, remove them or let them leave, and understand how seats are counted.

Written for
admin
Roles
owner, admin
Requires
Owner or Admin; Browser session with a recent re-authentication
Feature
members

Workspace users are the people who work in your workspace: they log time, see the projects they belong to, and hold one of three roles. Owners and admins manage them under Settings → People → Members. This page covers invitations, roles, removal, and seats. Client users are not managed here; see Manage client users.

Before you start

  • You need the Owner or Admin role. Members see the member list but cannot change it.
  • Inviting, changing a role, withdrawing an invitation, and removing someone each ask you to confirm your identity (password, passkey, a still-recent login, or your identity provider).
  • Invitations count against the plan's seats. Check Settings → Organization if you are close to the limit.

Invite a workspace user

  1. Open Settings → People → Members.
  2. Under Invite a workspace user, enter the person's Email and choose a Role.
  3. Select Send invitation and confirm your identity.

The invitation is emailed and is valid for 7 days. It appears under Pending invitations with Email, Role, Invited by, and Expires. Select Withdraw to cancel it; the link stops working immediately.

Only one invitation per address is live at a time. Sending a new invitation to the same address replaces the earlier link. An address that is already a member is refused with "This person is already a member of the workspace."

What the invitee sees

The email links to an invitation page that names the workspace and the role.

Situation What happens
No account for the address yet Create your account: the email is fixed, they choose a Name and a New password, then select Create account and join.
An account exists but they are logged out "There is already an account for {email}. Log in to accept the invitation."
Logged in with the invited address Join the workspace.
Logged in with a different address They are asked to log out and log in with the invited address.
Link expired, withdrawn, or already used A message says so; ask for a new invitation.

Invited owners and admins must set up two-factor authentication (an authenticator app or a passkey) before they can enter the workspace. Until they have, the app sends them to Account → Security.

Roles

Role Can do Who can assign it
Owner Everything, including the organization settings (plan, audit log, export, deletion). Owners only.
Admin Everything in the workspace except the organization settings. Owners and admins.
Member Day-to-day work on the projects they belong to. Owners and admins.

Rules:

  • An owner can assign any role. An admin can assign Admin or Member and can never change or remove an owner ("Only an owner can do this.").
  • A workspace always keeps at least one owner. Demoting or removing the last owner is refused with "A workspace needs at least one owner."
  • Owners and admins must have two-factor authentication. Promoting someone who has not enrolled lets them in only after they enrol.
  • Agent accounts always stay members ("Agent accounts stay workspace members.").

Change a role

  1. In the members table, change the Role for the person.
  2. Confirm in the dialog Change the role of {name} to {role}. The new permissions apply immediately.

Moving a person between Member and Owner or Admin, in either direction, revokes their personal API tokens, because those roles require two-factor authentication at minting. They create new tokens afterwards. See API tokens and agent accounts.

Remove a member

  1. Select Remove on the person's row.
  2. Confirm in Remove {name} from this workspace.

What happens immediately:

  • The membership ends, together with all project memberships and every ticket they were a viewer of.
  • Their API tokens for this workspace are revoked.
  • Their name on old tickets, comments, time entries, and audit rows becomes a placeholder such as "Former member 3". The records themselves stay, so counts and billing history are unchanged.
  • Their login and their other workspaces are not affected.

A removed person is not re-joined by single sign-on, even when JIT provisioning is on. A new invitation or a SCIM push brings them back, and their real name shows again.

Leave a workspace

Anyone can select Leave workspace on their own row. The effects are the same as a removal. The last owner cannot leave; hand ownership to someone else first.

Seats

Seats belong to the organization and are counted across all its workspaces. A seat is used by every workspace user and by every pending invitation. Client users, contacts, and agent accounts are free. When the plan has no seats left, inviting is refused with "This plan has no remaining seats." Withdraw stale invitations or remove people to free seats, or change the plan; see Plan, seats, and subscription.

Other kinds of accounts

  • Client users belong to a client and are managed under Clients, not here.
  • Agent accounts are token-only workspace users for integrations and AI agents, created at the bottom of the Members page. They appear in the members table marked "(agent)" with a fixed Member role. See API tokens and agent accounts.
  • With single sign-on and SCIM, the identity provider can create and deactivate workspace users. See Set up SCIM provisioning.

Common problems

Why can't I change this person's role? Admins cannot touch owners. Ask an owner.

The invitee cannot get in after accepting. Owners and admins are sent to Account → Security until two-factor authentication is set up.

"This workspace is read-only until the subscription is restored." Invitations cannot be accepted in a read-only workspace. See Plan, seats, and subscription.