> ## Documentation Index
> Fetch the complete documentation index at: https://docs.northernlogic.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Members and invitations

> Manage who belongs to your workspace and which role they hold.

Open **Team** to see workspace people and their details. Workspace owners and
admins manage invitations, people, and agent identities.

## Invite a teammate

1. Open **Team** and the invitation action.
2. Enter the person's email address and select the permitted workspace role.
3. Send the invitation. If email delivery is unavailable, use the provided
   invitation-link fallback.
4. Check the pending invitation and ask the person to accept using that exact
   email address.

Pending invitations count toward the seat limit. A newly accepted member
normally receives Company Viewer access and their own personal vault. Grant
additional [vault access](/collaboration/vault-access) separately.

Invitations expire after 72 hours and are single-use. Send a new invitation if
the old one can no longer be accepted.

## Choose a workspace role

| Role   | Responsibility                                                                        |
| ------ | ------------------------------------------------------------------------------------- |
| Member | Work in authorized vaults and use permitted product features.                         |
| Admin  | Manage ordinary members, groups, agents, shared vaults, and connections.              |
| Owner  | Admin capabilities plus management of owners/admins and owner-only workspace actions. |

Only owners can grant or revoke Owner and Admin roles. The final active owner
cannot be disabled or demoted.

## Open a person's record

Select **Open** from their Actions menu to inspect their display name, account
email, groups, and devices. Administrators can edit the display name and group
assignments. Account email is not edited from Team.

Use the person's Actions menu for group assignment and endpoint or agent setup.
**Connections** remains the detailed endpoint inventory.

## Use an agent identity

An agent/service principal is a named non-human identity that can own
connections and hold vault roles. It has no interactive human login and cannot
become an organization owner or admin. Service principals do not consume human
seats.

Give it only the vault access needed for its work. Naming an agent does not
start a hosted agent or run a model.

Use the deliberate [offboarding process](/administration/offboarding) when
someone leaves.

## Help a new member succeed

Send new members [Join your team](/getting-started/join-team). Use
[Employee onboarding](/tutorials/employee-onboarding) to create and verify a
short first-week reading path.
