Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Users and groups

Use Users & Groups to manage membership and job-based access. Owners and admins (administrators) can make changes; members can inspect the access visible to them.

Invite a user

  1. Select the intended workspace.
  2. Open Users & Groups and select Invite user.
  3. Enter the person's company-managed email address.
  4. Assign the minimum workspace role required.
  5. Add the person to existing job-function groups instead of recreating access as direct exceptions.
An invitation does not grant tools by itself. Effective access still depends on workspace policy, app availability, group grants, direct grants, and restrictions.
Invitations expire after 7 days; resending an invitation starts a fresh 7-day window. The invitee must verify their email address when accepting.

Change a role or transfer ownership

Owners can change any other member's role (member, admin, or owner) in the portal. You cannot change your own role. Role changes are recorded in Audit. Promotion to admin or owner does not grant tool access by itself.
There is no dedicated ownership-transfer feature. To hand off ownership:
  1. Promote the new owner.
  2. Have the new owner demote you.
Keep at least two owners at all times so the workspace is never one departure away from having no owner.

Create or change a group

Name groups for stable job functions such as service desk, billing, or security operations.
  1. Create or open the group.
  2. Add members.
  3. Grant only the apps or individual tools required for that function.
  4. Add restrictions for tools the group must not run.
  5. Review effective access for a representative member.
Prefer individual tool grants when the group does not need an entire app.

Use direct user access sparingly

A direct user grant or restriction is an exception to job-based policy. Record why it exists and review it when the person's responsibilities change. Restrictions win over grants.

Correct an invitation

Revoke an incorrect or unneeded invitation before it is accepted.

Offboard a user

This is the canonical offboarding procedure; other pages link here.
  1. Remove or suspend the company identity in the authoritative identity system.
  2. Remove direct Stackyapper membership if it is not provisioned, and remove the user from groups and any direct grants.
  3. Revoke the user's AI clients and API keys.
  4. Revoke the user's personal app authorizations.
  5. Review recent Audit activity and preserve required records.
See Understand access for the complete policy order.