> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.ibee.co.in/docs/platform-fundamentals/team-members-access-roles/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/_mcp/server. # Team Members & Access Roles > Invite team members to your IBEE Solutions organization, assign access roles (Admin, Technical, Collaborator, Billing), and control workspace-level permissions. Team management in IBEE Solutions is organization-level. The organization owner (Primary) invites team members, assigns access roles, and controls which workspaces each member can reach. Each role determines what the member sees and does — from full organization control to read-only workspace access or billing-only views. ## Access roles Every team member holds one of four access roles: | Role | Scope | Capabilities | | ---------------- | -------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | | **Admin** | Organization-wide | Full access — workspaces, resources, billing, team management, activity logs, support, and API tokens | | **Technical** | All or selected workspaces | Read & write access to compute, storage, network, tools, support, and resource activity. No billing or team management | | **Collaborator** | All or selected workspaces | Read-only access to resources and activity. Cannot create, edit, or delete resources, manage billing, or manage team members | | **Billing** | Organization billing | View and manage Billing Summary, Usage, Invoices, Payment Method, and Usage Limits. No workspace or resource access | ### Workspace-scoped roles **Technical** and **Collaborator** roles support workspace scoping: * **All workspaces** — the member accesses every workspace in the organization, including newly created ones * **Selected workspaces** — the member accesses only the workspaces chosen during invitation. Toggle each workspace on or off **Admin** and **Billing** roles are always organization-wide and cannot be workspace-scoped. > **Warning** > > Access roles and workspace scope cannot be edited in place. To change either one, remove the member and send a new invitation with the required role and workspace access. ### Permission details | Capability | Admin | Technical | Collaborator | Billing | | --------------------------------------------- | ----- | --------------- | --------------- | ------- | | View workspaces & resources | Yes | Yes | Yes (read-only) | No | | Create, edit, delete resources | Yes | Yes | No | No | | Create workspaces | Yes | No | No | No | | View billing (Summary, Invoices, etc.) | Yes | No | No | Yes | | Manage billing (Payment Method, Usage Limits) | Yes | No | No | Yes | | View team members | Yes | Yes (read-only) | Yes (read-only) | No | | Invite, remove, and resend invitations | Yes | No | No | No | | View Organization Details | Yes | Yes (read-only) | Yes (read-only) | No | | Edit Organization Details | Yes | No | No | No | | View activity logs | Yes | Yes | Yes | No | | Access support | Yes | Yes | No | No | | Create API tokens | Yes | No | No | No | ## Primary owner The organization creator is the **Primary owner**, who always holds the Admin role. The Primary owner: * Cannot be removed from the organization * Has full access to all workspaces and settings * Manages team members, along with any other Admins * Appears at the top of the Team Members table with a "Primary owner" label * Is the only user who can [transfer ownership](#transfer-ownership) ### Transfer ownership The Primary owner can hand ownership to another member. The new owner must already be an **active** member — invite them and wait until they accept first. 1. On the **Team Members** page, click **Transfer ownership** in the Primary owner's row. 2. Under **New primary owner**, select an active team member. 3. Type the organization name exactly as shown to confirm. 4. Click **Transfer ownership**. The selected member becomes the Primary owner. You stay in the organization as an **Admin** with full organization and workspace access. Billing, resources, KYC, workspaces, and notification preferences stay with the organization. ## Invite a team member Only organization **Admins** can invite team members. ### Go to Team In the portal sidebar (organization level), click **Team** under **Organization**. ### Click Add Team Member Click **Add Team Member** in the top right of the Team Members page. ### Enter email Enter the team member's **Email Address**. This is the only required field — the invitee fills in their name and profile on acceptance. ### Choose an access role Select one of the four roles: * **Admin** — full organization access * **Collaborator** — read-only workspace access * **Billing** — billing-only organization access * **Technical** — read & write workspace access ### Select workspace access (Technical and Collaborator only) For **Technical** and **Collaborator** roles, a workspace access table appears. Each workspace is listed with a toggle switch. * **Select all** — grants access to every workspace (including future ones) * **Toggle individual workspaces** — choose exactly which workspaces the member can access At least one workspace must be selected. ### Send the invitation Click **Send Invitation**. The invitee receives an email with a link to accept. > **Info** > > Invited members must **sign up** (or log in if they already have an IBEE account) and **accept the invitation** before they gain access. Access is not granted until acceptance. ## Notification types Each role carries default notification subscriptions: | Notification type | Description | | ----------------- | ------------------------------------------------------------------- | | **Technical** | Infrastructure alerts, maintenance windows, resource status changes | | **Billing** | Invoice notifications, payment confirmations, billing alerts | | **Abuse** | Abuse reports and compliance notifications | | **Emergency** | Critical infrastructure alerts, security incidents | ### Defaults by role | Role | Default notifications | | ---------------- | ------------------------------------------ | | **Admin** | Technical, Billing, Abuse, Emergency (all) | | **Technical** | Technical, Abuse, Emergency | | **Collaborator** | Technical | | **Billing** | Billing | ## Manage team members The **Team Members** page lists all members and invitations in a table with these columns: * **Member** — name and email address * **Access Role** — Admin, Technical, Collaborator, or Billing (color-coded badge) * **Workspace Access** — "All organization workspaces", specific workspace names, or "No workspace access" (Billing role) * **Status** — **Active** for members; **Invite sent** (awaiting acceptance), **Invite expired**, or **Invitation declined** for invitations * **Actions** — for Admins: **Resend** for sent or expired invitations, and the trash icon to remove a member or invitation Technical and Collaborator members can open the Team Members page to see who is in the organization, but they can't invite, remove, or change anyone. ### Resend an invitation For an invitation that shows **Invite sent** or **Invite expired**, click **Resend**. The invitee receives a new invitation email. ### Remove a team member Click the **trash icon** to remove a member. A confirmation dialog appears. Removal: * Revokes access to the organization immediately * Removes login access to all workspaces in the organization * Cannot be undone — re-invite to restore access To assign a different access role or workspace scope, remove the member and send a new invitation with the updated selections. ### Remove an invitation Sent, expired, and declined invitations appear in the table. Click the **trash icon** to delete an invitation. ## Accepting an invitation When invited, a team member: 1. Receives an email with invitation details (organization name, role, inviter). 2. Sees the invitation on the **Organizations** page — with the inviter, role, workspace access, and expiry date — and **Accept** and **Decline** buttons. 3. Clicking **Accept** grants access immediately with the assigned role and workspace scope. 4. Clicking **Decline** marks the invitation as declined. The admin can remove it or re-invite. Invitations expire. If an invitation has expired, ask the admin to click **Resend** on the Team Members page. > **Info** > > You can be a member of up to 20 organizations that you don't own. See [Limits & Quotas](/docs/platform-fundamentals/limits-and-quotas#organization-limits). ## FAQ **What happens when "All workspaces" is selected for a Technical member?** The member gains access to every current workspace and any workspace created in the future. This is equivalent to organization-scope access for that role. **Can a Billing role member see resources?** No. Billing members see only billing pages (Summary, Usage, Invoices, Payment Method, Usage Limits) and have no workspace or resource access. ## Related pages * [Organizations and tenancy model](/docs/platform-fundamentals/organizations-and-tenancy-model) * [Organization settings](/docs/platform-fundamentals/organization-settings) * [Activity logs](/docs/platform-fundamentals/activity-logs) * [API Tokens](/docs/tools/api-tokens) * [Dashboard & Navigation](/docs/getting-started/overview/dashboard) > Invite team members to your IBEE Solutions organization, assign access roles (Admin, Technical, Collaborator, Billing), and control workspace-level permissions.