Guides

Members & roles

Bring your colleagues into your organisation and give each the right level of access. Roles split building work from deciding on it, so you can put a real human check between an agent's proposal and the outside world.

Inviting members

Go to Settings → Members, enter a colleague's email, choose a role (Viewer by default), and send the invitation. They receive an email with a link:

Invitations expire after seven days; send a fresh one if it lapses.

The five roles

Rather than one long ladder, the roles separate building from deciding:

The right to decide approvals (Owner, Admin and Approver) is deliberately separable from the right to build agents — and no agent ever holds it. Roles are fixed in this release; custom roles aren't yet available.

Changing & removing

From the Members list an admin can change anyone's role at any time, and remove a member when they move on. A few safeguards:

If your organisation signs in through SSO, members are provisioned, suspended and reinstated automatically by your identity provider. There's nothing to manage by hand here.

Segregation of duties

Under Settings → Organisation there's a "Separate proposer and approver" setting, on by default. With it on, the person who started a run cannot approve that run's actions — the decision controls are hidden for them, with an explanation, though they can still see the request. That guarantees a genuine second pair of eyes on everything an agent proposes.

For Code Governance the rule is stronger and always on: whoever authored or triggered an AI-written change can never be the one who approves it. See Code Governance.

Next steps