> ## Documentation Index
> Fetch the complete documentation index at: https://docs.marketer.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Members and roles

> Manage account membership, workspace reach, invitations, roles, removal, and MCP seats.

People belong to the account. Give them one role across every workspace or a role for each selected workspace.

## Separate role from reach

| Reach mode              | Available choices                                                            | Use it when                                           |
| ----------------------- | ---------------------------------------------------------------------------- | ----------------------------------------------------- |
| **All workspaces**      | **Admin**, **Member**, or **Viewer**                                         | The person needs a consistent role across the account |
| **Selected workspaces** | **No access**, **Owner**, **Admin**, **Member**, or **Viewer** per workspace | Access or responsibility differs by client workspace  |

The account Owner is established through ownership, not offered as a normal **All workspaces** invitation role.

### Role behavior

| Role       | Customer-visible posture                                                                                                  |
| ---------- | ------------------------------------------------------------------------------------------------------------------------- |
| **Owner**  | Full control of the assigned workspace; account Owner also owns account billing and paid MCP-seat decisions               |
| **Admin**  | Full edit access within reach; an account Admin can also manage the account team, while a selected-workspace Admin cannot |
| **Member** | Creates and edits content in the workspaces they can reach                                                                |
| **Viewer** | Read-only; mutation controls are disabled and workspace **Plans & Billing** is hidden                                     |

The all-workspaces descriptions are:

* **Admin** — Full access to every workspace, and can manage the team.
* **Member** — Create and edit content in every workspace.
* **Viewer** — Read-only across every workspace.

## Invite teammates

Only account Owners and account Admins can invite people or change account membership and roles. A selected-workspace Admin does not gain account-team management from that workspace role alone.

<Steps>
  <Step title="Open the team surface">
    Go to **Settings** → **Members**, or use **Users** in an eligible Account overview.
  </Step>

  <Step title="Start an invitation">
    Select **Invite teammate** or **Invite your team** and enter one or more emails.
  </Step>

  <Step title="Choose reach">
    Select **All workspaces** or **Selected workspaces**. A selected-workspace invitation must include at least one workspace.
  </Step>

  <Step title="Assign roles">
    For selected workspaces, set the intended role on each row and leave every other workspace at **No access**.
  </Step>

  <Step title="Review and send">
    Confirm emails, reach, and roles. Marketer blocks self-invites, duplicates, existing members, and already-pending invites.
  </Step>
</Steps>

Invitations remain under **Pending invites** until accepted.

### Pending invitation states

* Use **Resend** when the original invitation expired or was missed.
* Use **Revoke** when the person should no longer be able to join.
* Recheck reach and roles before resending; do not rely on an old invitation's intent.

## Change an existing member

For all-workspace access, change the account-wide role. For selected access, expand the member and choose **No access**, **Owner**, **Admin**, **Member**, or **Viewer** for each workspace.

Use this sequence for a role change:

1. Identify whether the problem is role or reach.
2. Confirm the affected workspace rows.
3. Apply the smallest change.
4. Ask the member to reopen the workspace switcher.
5. Verify that read, edit, and billing visibility match the intended role.

Owners and administrators cannot manage the account Owner or their own account role like an ordinary member.

## Remove a member

Removing someone from the account immediately removes every workspace grant.

Before removal, review:

* active work and approval ownership;
* Slack identity links;
* MCP seats and connected agents;
* pending deliverables; and
* any provider identity that only that person can reauthorize.

Removing workspace reach is narrower than removing the account member. Prefer **No access** for specific workspaces when the person still belongs elsewhere in the account.

## MCP seats are a separate grant

An MCP seat is assigned per member and workspace. Workspace membership does not automatically grant external-agent access.

| Rule                                       | Effect                                                                                          |
| ------------------------------------------ | ----------------------------------------------------------------------------------------------- |
| Account Owner                              | Seat is implicit and cannot be revoked like a teammate seat                                     |
| Account Owner grants or removes paid seats | Seat changes are billing operations                                                             |
| Account Admin                              | Can manage invites and roles but cannot make paid seat changes                                  |
| No workspace access                        | A seat cannot be granted first; establish workspace reach                                       |
| Seat removed                               | MCP access to that workspace is revoked; unused billed time can be credited on the next invoice |

The confirmation shows the applicable amount or billing treatment. Review the amount displayed rather than relying on a remembered price.

After a seat change, check the member row and [MCP connect](/workspace-admin/mcp-connect) sessions. A connection can remain listed while losing entitlement to a workspace.

## Common access problems

| Symptom                               | Check                                                |
| ------------------------------------- | ---------------------------------------------------- |
| Workspace is absent from the switcher | Selected-workspace grant is **No access** or missing |
| Controls are disabled                 | Effective role is **Viewer**                         |
| **Plans & Billing** is missing        | Viewer role, or billing belongs to an account plan   |
| Person can edit the wrong workspace   | Reach mode or per-workspace row is too broad         |
| MCP cannot use a visible workspace    | MCP seat or session workspace grant is missing       |
| Invitation never arrived              | **Pending invites**, email spelling, then **Resend** |

## Quarterly access review

* Confirm every active person still needs account membership.
* Prefer **Selected workspaces** where account-wide reach is unnecessary.
* Use **Viewer** for review-only collaborators.
* Revoke stale pending invitations.
* Match MCP seats and connected sessions to current responsibilities.
* Remove former teammates promptly.

## Next step

Review [Workspace switching](/workspace-admin/workspace-switching), then align each workspace's [Guardrails and autonomy](/workspace-admin/guardrails-and-autonomy) with the people who can act there.


## Related topics

- [Slack](/integrations/slack.md)
- [Shopify](/integrations/shopify.md)
- [Audience segments](/workspace-admin/audiences.md)
- [Google Analytics 4](/integrations/google-analytics-4.md)
- [Google Ads](/integrations/google-ads.md)
