Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Invite your team

Invite additional users only after the first app, AI client, provider read, and audit record have been verified. Manage normal access through groups, not per-user grants.

Plan access before inviting

Define groups around job responsibilities, not individual providers. Examples include:
  • Service desk readers
  • Security reviewers
  • Account and reporting users
  • Documentation users
  • Workspace administrators
Start each group with the smallest useful set of apps and read tools. Add write access only for a documented workflow with an accountable owner. Check the workspace selector before inviting users or changing group permissions.
  1. Create a group
    Open Users & Groups, select Groups, and create a group with a clear purpose and description.
  2. Assign permissions
    Add the required app or individual tool grants. Use restrictions when a group must not reach a sensitive tool that might otherwise be granted.
  3. Invite the user
    Open Users, add the person's company email, choose the appropriate role, and assign the planned groups.
  4. Have the user sign in
    The user should follow the invitation and authenticate with the matching verified company account.
  5. Connect personal apps
    If an enabled app uses personal credentials, each user must authorize their own provider account before using it.
  6. Verify effective access
    Use the Permissions view to inspect the user's effective access. Test one expected allowed read and, where appropriate, one expected denial.

Roles and tool access are different

Every user has one workspace role: owner, admin, or member. Owners and admins can manage the workspace — apps, users, groups, and settings — while members use the access they have been granted.
A portal role controls administrative actions and page visibility. App and tool grants control what the user's AI client can discover and execute. Giving someone an admin role should not be used as a substitute for designing their tool access.

MSP customer workspaces

Do not invite a customer user into the MSP's internal company workspace as a shortcut. Create or select the customer's isolated workspace instead — see Managed customers.

Ongoing review

Review group membership, tool grants, and audit activity whenever someone changes roles or leaves the company.