Team Members & Access Roles
Team management in IBEE Solutions is organization-level. The organization owner (Primary) invites team members, assigns access roles, and controls which workspaces each member can reach. Each role determines what the member sees and does — from full organization control to read-only workspace access or billing-only views.
Access roles
Every team member holds one of four access roles:
Workspace-scoped roles
Technical and Collaborator roles support workspace scoping:
- All workspaces — the member accesses every workspace in the organization, including newly created ones
- Selected workspaces — the member accesses only the workspaces chosen during invitation. Toggle each workspace on or off
Admin and Billing roles are always organization-wide and cannot be workspace-scoped.
Access roles and workspace scope cannot be edited in place. To change either one, remove the member and send a new invitation with the required role and workspace access.
Permission details
Primary owner
The organization creator is the Primary owner, who always holds the Admin role. The Primary owner:
- Cannot be removed from the organization
- Has full access to all workspaces and settings
- Manages team members, along with any other Admins
- Appears at the top of the Team Members table with a “Primary owner” label
- Is the only user who can transfer ownership
Transfer ownership
The Primary owner can hand ownership to another member. The new owner must already be an active member — invite them and wait until they accept first.
- On the Team Members page, click Transfer ownership in the Primary owner’s row.
- Under New primary owner, select an active team member.
- Type the organization name exactly as shown to confirm.
- Click Transfer ownership.
The selected member becomes the Primary owner. You stay in the organization as an Admin with full organization and workspace access. Billing, resources, KYC, workspaces, and notification preferences stay with the organization.
Invite a team member
Only organization Admins can invite team members.
Enter email
Enter the team member’s Email Address. This is the only required field — the invitee fills in their name and profile on acceptance.
Choose an access role
Select one of the four roles:
- Admin — full organization access
- Collaborator — read-only workspace access
- Billing — billing-only organization access
- Technical — read & write workspace access
Select workspace access (Technical and Collaborator only)
For Technical and Collaborator roles, a workspace access table appears. Each workspace is listed with a toggle switch.
- Select all — grants access to every workspace (including future ones)
- Toggle individual workspaces — choose exactly which workspaces the member can access
At least one workspace must be selected.
Invited members must sign up (or log in if they already have an IBEE account) and accept the invitation before they gain access. Access is not granted until acceptance.
Notification types
Each role carries default notification subscriptions:
Defaults by role
Manage team members
The Team Members page lists all members and invitations in a table with these columns:
- Member — name and email address
- Access Role — Admin, Technical, Collaborator, or Billing (color-coded badge)
- Workspace Access — “All organization workspaces”, specific workspace names, or “No workspace access” (Billing role)
- Status — Active for members; Invite sent (awaiting acceptance), Invite expired, or Invitation declined for invitations
- Actions — for Admins: Resend for sent or expired invitations, and the trash icon to remove a member or invitation
Technical and Collaborator members can open the Team Members page to see who is in the organization, but they can’t invite, remove, or change anyone.
Resend an invitation
For an invitation that shows Invite sent or Invite expired, click Resend. The invitee receives a new invitation email.
Remove a team member
Click the trash icon to remove a member. A confirmation dialog appears. Removal:
- Revokes access to the organization immediately
- Removes login access to all workspaces in the organization
- Cannot be undone — re-invite to restore access
To assign a different access role or workspace scope, remove the member and send a new invitation with the updated selections.
Remove an invitation
Sent, expired, and declined invitations appear in the table. Click the trash icon to delete an invitation.
Accepting an invitation
When invited, a team member:
- Receives an email with invitation details (organization name, role, inviter).
- Sees the invitation on the Organizations page — with the inviter, role, workspace access, and expiry date — and Accept and Decline buttons.
- Clicking Accept grants access immediately with the assigned role and workspace scope.
- Clicking Decline marks the invitation as declined. The admin can remove it or re-invite.
Invitations expire. If an invitation has expired, ask the admin to click Resend on the Team Members page.
You can be a member of up to 20 organizations that you don’t own. See Limits & Quotas.
FAQ
What happens when “All workspaces” is selected for a Technical member? The member gains access to every current workspace and any workspace created in the future. This is equivalent to organization-scope access for that role.
Can a Billing role member see resources? No. Billing members see only billing pages (Summary, Usage, Invoices, Payment Method, Usage Limits) and have no workspace or resource access.
