Separate role from reach
The account Owner is established through ownership, not offered as a normal All workspaces invitation role.
Role behavior
The all-workspaces descriptions are:
- Admin — Full access to every workspace, and can manage the team.
- Member — Create and edit content in every workspace.
- Viewer — Read-only across every workspace.
Invite teammates
Only account Owners and account Admins can invite people or change account membership and roles. A selected-workspace Admin does not gain account-team management from that workspace role alone.1
Open the team surface
Go to Settings → Members, or use Users in an eligible Account overview.
2
Start an invitation
Select Invite teammate or Invite your team and enter one or more emails.
3
Choose reach
Select All workspaces or Selected workspaces. A selected-workspace invitation must include at least one workspace.
4
Assign roles
For selected workspaces, set the intended role on each row and leave every other workspace at No access.
5
Review and send
Confirm emails, reach, and roles. Marketer blocks self-invites, duplicates, existing members, and already-pending invites.
Pending invitation states
- Use Resend when the original invitation expired or was missed.
- Use Revoke when the person should no longer be able to join.
- Recheck reach and roles before resending; do not rely on an old invitation’s intent.
Change an existing member
For all-workspace access, change the account-wide role. For selected access, expand the member and choose No access, Owner, Admin, Member, or Viewer for each workspace. Use this sequence for a role change:- Identify whether the problem is role or reach.
- Confirm the affected workspace rows.
- Apply the smallest change.
- Ask the member to reopen the workspace switcher.
- Verify that read, edit, and billing visibility match the intended role.
Remove a member
Removing someone from the account immediately removes every workspace grant. Before removal, review:- active work and approval ownership;
- Slack identity links;
- MCP seats and connected agents;
- pending deliverables; and
- any provider identity that only that person can reauthorize.
MCP seats are a separate grant
An MCP seat is assigned per member and workspace. Workspace membership does not automatically grant external-agent access.
The confirmation shows the applicable amount or billing treatment. Review the amount displayed rather than relying on a remembered price.
After a seat change, check the member row and MCP connect sessions. A connection can remain listed while losing entitlement to a workspace.
Common access problems
Quarterly access review
- Confirm every active person still needs account membership.
- Prefer Selected workspaces where account-wide reach is unnecessary.
- Use Viewer for review-only collaborators.
- Revoke stale pending invitations.
- Match MCP seats and connected sessions to current responsibilities.
- Remove former teammates promptly.