Managing members
Inviting people, assigning roles, resetting passwords, and removing access.
Organization → Members lists everyone in the organization with their role and team memberships.
Adding a member
New member asks for four things:
| Field | Notes |
|---|---|
| Username | What they sign in with and how they appear in the app. Fixed after creation. |
| Also usable to sign in. Fixed after creation. | |
| Password | Minimum 8 characters. You set it; there is no invitation email flow. |
| Role | member or org admin. See Roles. |
Send them the credential over whatever channel you would send any initial password, and point them at Install the desktop app.
Username and email are fixed
Editing an existing member covers role and password only. If someone's address changes, create a new member and disable the old one — the audit trail stays coherent that way.
If you hit the seat limit
You're at your seat limit (n). Add seats to invite more.
Buy more seats on the Account page, or disable someone who no longer needs access — a disabled member does not consume a seat. See Roles, plans and seats.
Editing a member
The edit dialog covers:
- Role — promote to org admin or demote to member.
- New password — leave blank to keep the current one. This is how you reset a password for someone who is locked out.
Team membership is not edited here. It lives on the team, in the Teams tab — see Teams.
Removing someone
The delete button disables the account rather than deleting it. They lose access immediately — the next authenticated call from their desktop fails, so this is not something they can outrun by staying signed in.
The row stays, marked disabled, with an Enable button to reverse it. This is deliberate: synced desktop installs keep their history and its attribution intact, so "who ran this investigation" still has an answer after someone leaves.
The owner's row
The account owner appears in the list with an owner badge and no edit or disable controls — just a pointer to Account settings.
They have no membership row underneath; they are projected into the list from the account so that one human keeps one password and still shows up in every directory read. Their email, password and role are all managed on the Account page. They also cannot be added to a team, for the same reason: team membership is a reference to a member row the owner does not have.
Guardrails
- You cannot change your own role.
- You cannot disable yourself.
Both are enforced server-side, not just hidden in the UI, so an organization cannot end up with nobody able to administer it.
What members see of all this
A member can open the Organization page and see the roster and the teams. They cannot create, edit or disable anyone, and the spend cap and default-connector cards are not rendered for them at all.