Invite and manage people
Bring colleagues into your organization, give them the right role, and remove them without leaving broken shared tooling behind.
Where to find it: Settings → People → Members
You need the Manage members permission (member:manage) to invite people, change roles, revoke pending invites, or remove members. Anyone in the organization can see the People list.
Ways people join
| Path | How it works | Starting role |
|---|---|---|
| Invite | You email a single-use activation link with a pre-assigned role. | The role you select on the invite. |
| Verified domain | Someone with an email on a verified org domain signs in and joins automatically. | The domain’s default role, or Member if none is set. |
| SCIM | Your identity provider provisions users (and optionally groups). | Group → role mappings when configured; otherwise Member. |
Invites are the day-to-day path. Domain join and SCIM are the invite-free paths — see Provisioning members with SCIM and your domain settings under Settings → Organization / Settings → SSO.
Invite someone
- Open Settings → People → Members.
- Choose Invite member.
- Enter their exact work email — the activation link is bound to that address.
- Select one role (built-in or custom). Everyone holds exactly one role — it is the whole of what they can do.
- Choose Send invite.
Elaichi emails a seven-day single-use link. The dialog also shows the raw invite link once so you can copy it for chat or a ticket if email doesn’t arrive. Anyone with that link can activate the account for the invited email — treat it like a secret.
You'll know it worked when: The person appears under Pending invites until they click the link, then moves into the People list with the role you chose.
What happens when they accept
Clicking the link proves the invited email, creates or finds their user account, accepts the invite, and starts a session — they don’t need a separate magic-link login for that first join.
Pending invites
Below the People table, Pending invites lists emails that haven’t joined yet.
| Action | Effect |
|---|---|
| Revoke | Cancels the invite. The link stops working. |
There is no resend control in the UI — revoke and send a new invite if the link expired or was lost.
Change someone’s role
- Find the person in the People list.
- Open the role control on their row.
- Pick the new role. It replaces the one they had — a promotion swaps the role, it never stacks a second one on top. Changes apply immediately, including to people who are already signed in.
Member is the usual default for new joiners. Prefer starting narrow and moving someone up a tier later rather than assigning Org Admin broadly. See Roles and permissions for the full catalog.
People can also belong to teams (shown on the same row). Team membership is managed under Settings → People → Teams, not on the invite dialog.
Remove a member
Removing someone immediately cuts their access to the organization. Before that finishes, Elaichi runs an offboarding check on everything they own — connections, synthetic tools, toolboxes and templates.
- Open the row menu → Remove from organization.
- Review what they own:
- Connections used by shared toolboxes are flagged Used by shared toolboxes.
- Toolboxes and templates other people can reach are flagged the same way, and these must be resolved: nothing but ownership can delete or transfer one, so a shared toolbox left behind is unmanageable by everybody.
- Synthetic tools go with their author — they can’t be shared or transferred — so the only thing to confirm is the ones somebody else’s toolbox pins.
- Either pick one successor under Give everything to, or choose an action per resource (defaults are chosen for you — change them before confirming):
| Choice | Use when | Default when |
|---|---|---|
| Transfer to member | A colleague is taking the account over | Connection is referenced by shared toolboxes |
| Delete connection | Truly personal, and nobody else needs it | Connection is not referenced |
Transfer moves ownership only — it never widens who can reach the connection, which is why there is no “transfer to organization” or “transfer to team” choice. Share the connection separately if more people need it.
- Confirm Remove member.
If a referenced personal connection — or any shared toolbox or template — isn’t resolved, removal is refused until you transfer or delete it. Unreferenced personal connections, private toolboxes and private templates left on Delete are cleaned up with the member. If they own a very large estate, the first confirm may report that some of it was resolved and more remains: the work done is kept, the member stays, and you confirm again to finish. Credentials move with a transfer — toolboxes that already used the connection keep working.
You can’t remove yourself from the People list. The last Org Owner can’t be removed or demoted until someone else is an Owner.
For the full transfer flow outside of removal, see Transfer and offboard.
Good to know
- Invites require
member:manage. Role assignment and removal use the same permission. - An organization always keeps at least one Org Owner.
- New joiners via domain or SCIM (with no group mapping) get Member unless you configure another default.
- After someone joins, add them to teams under Teams so shared connections and toolbox shares reach them as a group.