Skip to main content
Each team member has an organization role, and you can override it for individual tenants.

What each role can do

Managing the organization covers team members, billing, single sign-on, the audit log, and creating tenants. This follows the organization role, so giving someone Admin in one tenant lets them manage that tenant but not the organization. Use Support analyst for a support agent who needs to investigate user activity and reset authenticators.

Tenant access

Under Tenant access, each tenant has its own control:
  • The organization role gives them whatever their organization role is, and follows it when you change it.
  • A specific role overrides their organization role in that tenant.
  • No access hides the tenant from them.
For example, a team member with the Read only organization role can be set to Admin in a single tenant, so they manage that one tenant and only view the rest.

Add a team member

You need the Admin organization role to add or change team members.
  1. Open Organization settings > Team.
  2. Click Add team member.
  3. Enter their Full name and Email.
  4. Choose an Organization role.
  5. Under Tenant access, set the role for each tenant they need. Leave the rest on No access.
  6. Click Add team member to send the invitation.
They stay Pending invitation in the team list until they accept. To send the invitation again, use the refresh icon next to that status.

Change roles or tenant access

  1. Open Organization settings > Team and select the team member’s name.
  2. Under Access and roles, change their Organization role, change the role for any tenant, or set a tenant to No access to revoke it.
  3. Click Save changes.
Changing the organization role also changes it in every tenant that follows it.

Deactivate a team member

Deactivating is how you remove someone from the organization. It takes away their access to the organization and all of its tenants, and stops them signing in.
  1. Open Organization settings > Team and select the team member’s name.
  2. Click Deactivate team member.
Their roles and tenant access are kept, so you can open them again and click Activate team member to restore exactly what they had.