> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.ai/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.ai/docs/_mcp/server.

# Team Members & Access Roles

> Invite team members to your IBEE Solutions organization, assign access roles (Admin, Technical, Collaborator, Billing), and control workspace-level permissions.

Team management in IBEE Solutions is organization-level. The organization owner (Primary) invites team members, assigns access roles, and controls which workspaces each member can reach. Each role determines what the member sees and does — from full organization control to read-only workspace access or billing-only views.

## Access roles

Every team member holds one of four access roles:

| Role             | Scope                      | Capabilities                                                                                                                 |
| ---------------- | -------------------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| **Admin**        | Organization-wide          | Full access — workspaces, resources, billing, team management, activity logs, support, and API tokens                        |
| **Technical**    | All or selected workspaces | Read & write access to compute, storage, network, tools, support, and resource activity. No billing or team management       |
| **Collaborator** | All or selected workspaces | Read-only access to resources and activity. Cannot create, edit, or delete resources, manage billing, or manage team members |
| **Billing**      | Organization billing       | View and manage Billing Summary, Invoices, Payment Method, and Usage Limits. No workspace or resource access                 |

### Workspace-scoped roles

**Technical** and **Collaborator** roles support workspace scoping:

* **All workspaces** — the member accesses every workspace in the organization, including newly created ones
* **Selected workspaces** — the member accesses only the workspaces chosen during invitation. Toggle each workspace on or off

**Admin** and **Billing** roles are always organization-wide and cannot be workspace-scoped.

> **Warning**
>
> Access roles and workspace scope cannot be edited in place. To change either one, remove the member and send a new invitation with the required role and workspace access.

### Permission details

| Capability                                    | Admin | Technical | Collaborator    | Billing |
| --------------------------------------------- | ----- | --------- | --------------- | ------- |
| View workspaces & resources                   | Yes   | Yes       | Yes (read-only) | No      |
| Create, edit, delete resources                | Yes   | Yes       | No              | No      |
| Create workspaces                             | Yes   | No        | No              | No      |
| View billing (Summary, Invoices, etc.)        | Yes   | No        | No              | Yes     |
| Manage billing (Payment Method, Usage Limits) | Yes   | No        | No              | Yes     |
| View & manage team members                    | Yes   | No        | No              | No      |
| View activity logs                            | Yes   | Yes       | Yes             | No      |
| Access support                                | Yes   | Yes       | No              | No      |
| Create API tokens                             | Yes   | No        | No              | No      |

## Primary owner

The organization creator is the **Primary owner** — permanently assigned the Admin role. The Primary owner:

* Cannot be removed from the organization
* Has full access to all workspaces and settings
* Is the only user who can manage team members (along with other Admins)
* Appears at the top of the Team Members table with a "Primary owner" label

## Invite a team member

Only organization **Admins** can invite team members.

### Go to Team

In the portal sidebar (organization level), click **Team** under **Organization**.

### Click Add Team Member

Click **Add Team Member** in the top right of the Team Members page.

### Enter email

Enter the team member's **Email Address**. This is the only required field — the invitee fills in their name and profile on acceptance.

### Choose an access role

Select one of the four roles:

* **Admin** — full organization access
* **Collaborator** — read-only workspace access
* **Billing** — billing-only organization access
* **Technical** — read & write workspace access

### Select workspace access (Technical and Collaborator only)

For **Technical** and **Collaborator** roles, a workspace access table appears. Each workspace is listed with a toggle switch.

* **Select all** — grants access to every workspace (including future ones)
* **Toggle individual workspaces** — choose exactly which workspaces the member can access

At least one workspace must be selected.

### Send the invitation

Click **Send Invitation**. The invitee receives an email with a link to accept.

> **Info**
>
> Invited members must **sign up** (or log in if they already have an IBEE account) and **accept the invitation** before they gain access. Access is not granted until acceptance.

## Notification types

Each role carries default notification subscriptions:

| Notification type | Description                                                         |
| ----------------- | ------------------------------------------------------------------- |
| **Technical**     | Infrastructure alerts, maintenance windows, resource status changes |
| **Billing**       | Invoice notifications, payment confirmations, billing alerts        |
| **Abuse**         | Abuse reports and compliance notifications                          |
| **Emergency**     | Critical infrastructure alerts, security incidents                  |

### Defaults by role

| Role             | Default notifications                      |
| ---------------- | ------------------------------------------ |
| **Admin**        | Technical, Billing, Abuse, Emergency (all) |
| **Technical**    | Technical, Abuse, Emergency                |
| **Collaborator** | Technical                                  |
| **Billing**      | Billing                                    |

## Manage team members

The **Team Members** page lists all members and pending invitations in a table with these columns:

* **Member** — name and email address
* **Access Role** — Admin, Technical, Collaborator, or Billing (color-coded badge)
* **Workspace Access** — "All organization workspaces", specific workspace names, or "No workspace access" (Billing role)
* **Status** — Active, Pending (invitation sent), or Declined
* **Actions** — Remove (trash icon), visible to Admins for removable members and invitations

### Remove a team member

Click the **trash icon** to remove a member. A confirmation dialog appears. Removal:

* Revokes access to the organization immediately
* Removes login access to all workspaces in the organization
* Cannot be undone — re-invite to restore access

To assign a different access role or workspace scope, remove the member and send a new invitation with the updated selections.

### Remove a pending invitation

Pending and declined invitations appear in the table. Click the **trash icon** to delete an invitation.

## Accepting an invitation

When invited, a team member:

1. Receives an email with invitation details (organization name, role, inviter).
2. Sees a banner on the **Organizations** page with **Accept** and **Decline** buttons.
3. Clicking **Accept** grants access immediately with the assigned role and workspace scope.
4. Clicking **Decline** marks the invitation as declined. The admin can remove it or re-invite.

Invitations expire. If expired, the admin must send a new invitation.

## FAQ

**What happens when "All workspaces" is selected for a Technical member?**
The member gains access to every current workspace and any workspace created in the future. This is equivalent to organization-scope access for that role.

**Can a Billing role member see resources?**
No. Billing members see only billing pages (Summary, Invoices, Payment Method, Usage Limits) and have no workspace or resource access.

## Related pages

* [Organizations and tenancy model](/docs/platform-fundamentals/projects-and-tenancy-model)
* [API Tokens](/docs/tools/api-tokens)
* [Dashboard & Navigation](/docs/getting-started/overview/dashboard)