Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Users and groups

Use Users & Groups to manage membership and job-based access. Owners and administrators can make changes; members can inspect the access visible to them.

Invite a user

  1. Select the intended workspace.
  2. Open Users & Groups and select Invite user.
  3. Enter the person's company-managed email address.
  4. Assign the minimum workspace role required.
  5. Add the person to existing job-function groups instead of recreating access as direct exceptions.
An invitation does not grant tools by itself. Effective access still depends on workspace policy, app availability, group grants, direct grants, and explicit restrictions.

Create or change a group

Name groups for stable job functions such as service desk, billing, or security operations.
  1. Create or open the group.
  2. Add members.
  3. Grant only the apps or individual tools required for that function.
  4. Add explicit restrictions for tools the group must not run.
  5. Review effective access for a representative member.
  6. Verify a bounded read and its Audit record.
Prefer individual tool grants when the group does not need an entire app.

Use direct user access sparingly

A direct user grant or restriction is an exception to job-based policy. Record why it exists and review it when the person's responsibilities change. Restrictions win over grants.

Offboard or correct an invitation

Revoke an incorrect or unneeded invitation. When offboarding a user, remove or suspend the authoritative company identity, revoke the user's AI clients and personal app authorizations, then review recent Audit activity.
See Understand access for the complete policy order and Administrator runbooks for the offboarding sequence.