Users, Roles, and Teams
Open Settings → Users (/settings/users) to control who belongs to the organization and what each person can do. The old /admin/users address only redirects to this page.
People with users.view can read the list. Changing members, invitations, or roles requires access_control.manage; the organization owner also has this access.
What appears on the page
Section titled “What appears on the page”The Users tab combines active, inactive, plan-restricted members and pending invitations. The table shows name, email, last login, role or team, status, and the actions menu.
The other tabs depend on the organization’s configuration:
- with granular permissions enabled, access administrators see Roles;
- in the legacy model, access administrators see Teams;
- people with read-only permission see Users only, with mutation controls disabled.
Find and filter people
Section titled “Find and filter people”Search by name or email. The Status filter offers All, Active, Inactive, and Pending. The last filter changes with the organization’s model: Role in the granular model or Team in the legacy model.
Invitations that have not been accepted appear in the same list with the Pending invite badge and Pending status. They cannot be included in bulk actions.
Roles and permissions
Section titled “Roles and permissions”In the current model, a person can have more than one role. Permissions from all selected packages are added together:
| Role | Intended for | Important limit |
|---|---|---|
| Administrator | People who must manage agents, channels, conversations, contacts, knowledge, reports, API, and the team | Cannot manage billing, close the organization, or transfer ownership |
| AI Agents | People who create, configure, connect, and publish AI Agents | Cannot handle conversations or manage contacts, the team, API, webhooks, or reports |
| Support | People working with CRM, conversations, contacts, quick replies, and emails | Cannot create AI Agents, connect channels, delete knowledge bases, or view reports |
| Collaborator | People using the Hub, Rooms, and internal meetings | Cannot access customer conversations, contacts, AI Agents, or settings |
| Custom | One person who needs individually selected permissions | Belongs to that person only; it is not a shared package |
Open the Roles tab to read the complete summary of what each package can and cannot do. Custom starts with Rooms access and opens a capability checklist for individual selection.
The Owner is not a selectable role. Each organization has exactly one owner, with full access and exclusive authority over billing, organization closure, and ownership transfer.
Invite a person
Section titled “Invite a person”- On the Users tab, select Invite.
- Enter Name and Email.
- Select one or more Roles. For a specific combination, select Custom and check the required permissions.
- Select Send Invite.
A valid pending invitation counts against the plan limit. When the limit is reached, Invite is disabled and the page offers seat management or an upgrade.
The person receives an email and must complete the flow in Accept an invitation. From the pending invitation’s menu, select Resend invite or Cancel invite.
Edit, suspend, or remove access
Section titled “Edit, suspend, or remove access”Open a member’s three-dot menu and select Edit. You can:
- change the display name; the sign-in email is read-only;
- change one or more roles and, for Custom, review capabilities;
- suspend access;
- remove the person from the organization.
The owner’s role cannot be changed and the owner cannot be removed through this flow. In the owner’s row menu, only the owner sees Transfer ownership. The destination must be an active administrator; after the transfer, the previous owner becomes an administrator.
Bulk actions
Section titled “Bulk actions”Select active members in the first column to display the selection bar. In the granular model, Change role applies one of the four predefined packages to everyone selected; Custom is not available in bulk. You can also Suspend the selected members.
In the legacy model, the actions are Change Role, Change Team, and Suspend. Bulk promotion to administrator and larger suspension batches require additional confirmation.
Plan seats
Section titled “Plan seats”When the plan has a user limit, the counter includes current members and pending invitations. Manage seats lets you choose which members occupy the available seats. The owner is always active; anyone left out keeps their account, receives the No plan seat badge, and regains access when a seat is released.
Teams in the legacy model
Section titled “Teams in the legacy model”Organizations that have not migrated to granular roles see the Teams tab. Each team can control agent categories, agentless conversations, access to the model selector, and allowed models. Teams can also be created, edited, deleted, and viewed as a list or cards.
Do not create a team to represent a role in the granular model. Assign packages directly to the person or use Custom instead.
Best practices
Section titled “Best practices”- Grant only the required roles; packages accumulate permissions.
- Reserve Administrator for people who actually manage access and organization settings.
- Use Custom for individual exceptions, not as the default role.
- Review pending invitations, inactive people, and plan seats regularly.
- Transfer ownership before the current owner leaves the organization.
- Use individual corporate emails and never share accounts.