Skip to main content
People belong to the account. Give them one role across every workspace or a role for each selected workspace.

Separate role from reach

The account Owner is established through ownership, not offered as a normal All workspaces invitation role.

Role behavior

The all-workspaces descriptions are:
  • Admin — Full access to every workspace, and can manage the team.
  • Member — Create and edit content in every workspace.
  • Viewer — Read-only across every workspace.

Invite teammates

Only account Owners and account Admins can invite people or change account membership and roles. A selected-workspace Admin does not gain account-team management from that workspace role alone.
1

Open the team surface

Go to Settings → Members, or use Users in an eligible Account overview.
2

Start an invitation

Select Invite teammate or Invite your team and enter one or more emails.
3

Choose reach

Select All workspaces or Selected workspaces. A selected-workspace invitation must include at least one workspace.
4

Assign roles

For selected workspaces, set the intended role on each row and leave every other workspace at No access.
5

Review and send

Confirm emails, reach, and roles. Marketer blocks self-invites, duplicates, existing members, and already-pending invites.
Invitations remain under Pending invites until accepted.

Pending invitation states

  • Use Resend when the original invitation expired or was missed.
  • Use Revoke when the person should no longer be able to join.
  • Recheck reach and roles before resending; do not rely on an old invitation’s intent.

Change an existing member

For all-workspace access, change the account-wide role. For selected access, expand the member and choose No access, Owner, Admin, Member, or Viewer for each workspace. Use this sequence for a role change:
  1. Identify whether the problem is role or reach.
  2. Confirm the affected workspace rows.
  3. Apply the smallest change.
  4. Ask the member to reopen the workspace switcher.
  5. Verify that read, edit, and billing visibility match the intended role.
Owners and administrators cannot manage the account Owner or their own account role like an ordinary member.

Remove a member

Removing someone from the account immediately removes every workspace grant. Before removal, review:
  • active work and approval ownership;
  • Slack identity links;
  • MCP seats and connected agents;
  • pending deliverables; and
  • any provider identity that only that person can reauthorize.
Removing workspace reach is narrower than removing the account member. Prefer No access for specific workspaces when the person still belongs elsewhere in the account.

MCP seats are a separate grant

An MCP seat is assigned per member and workspace. Workspace membership does not automatically grant external-agent access. The confirmation shows the applicable amount or billing treatment. Review the amount displayed rather than relying on a remembered price. After a seat change, check the member row and MCP connect sessions. A connection can remain listed while losing entitlement to a workspace.

Common access problems

Quarterly access review

  • Confirm every active person still needs account membership.
  • Prefer Selected workspaces where account-wide reach is unnecessary.
  • Use Viewer for review-only collaborators.
  • Revoke stale pending invitations.
  • Match MCP seats and connected sessions to current responsibilities.
  • Remove former teammates promptly.

Next step

Review Workspace switching, then align each workspace’s Guardrails and autonomy with the people who can act there.
Last modified on August 9, 2026