Use Users & Groups to manage membership and job-based access. Owners and
admins (administrators) can make changes; members can inspect the access
visible to them.
Invite a user
Select the intended workspace.
Open Users & Groups and select Invite user.
Enter the person's company-managed email address.
Assign the minimum workspace role required.
Add the person to existing job-function groups instead of recreating access
as direct exceptions.
An invitation does not grant tools by itself. Effective access still depends on
workspace policy, app availability, group grants, direct grants, and
restrictions.
Invitations expire after 7 days; resending an invitation starts a fresh 7-day
window. The invitee must verify their email address when accepting.
Change a role or transfer ownership
Owners can change any other member's role (member, admin, or owner) in the
portal. You cannot change your own role. Role changes are recorded in Audit.
Promotion to admin or owner does not grant tool access by itself.
There is no dedicated ownership-transfer feature. To hand off ownership:
Promote the new owner.
Have the new owner demote you.
Keep at least two owners at all times so the workspace is never one departure
away from having no owner.
Create or change a group
Name groups for stable job functions such as service desk, billing, or
security operations.
Create or open the group.
Add members.
Grant only the apps or individual tools required for that function.
Add restrictions for tools the group must not run.
Review effective access for a representative member.
Prefer individual tool grants when the group does not need an entire app.
Use direct user access sparingly
A direct user grant or restriction is an exception to job-based policy. Record
why it exists and review it when the person's responsibilities change.
Restrictions win over grants.
Correct an invitation
Revoke an incorrect or unneeded invitation before it is accepted.
Offboard a user
This is the canonical offboarding procedure; other pages link here.
Remove or suspend the company identity in the authoritative identity
system.
Remove direct Stackyapper membership if it is not provisioned, and remove
the user from groups and any direct grants.
Revoke the user's AI clients and API keys.
Revoke the user's personal app authorizations.
Review recent Audit activity and preserve required records.