Organization Membership
Members join your Organization in one of two ways. These methods are mutually exclusive — you will use one or the other, not both.Single Sign-On (SSO)
If your company uses an Identity Provider (Okta, Google Workspace, Microsoft Entra, JumpCloud) with SSO configured, Members authenticate through your IdP and are automatically provisioned into your Organization. See Single Sign-On (SSO) for setup instructions.Invitation-Based
Invitation-based Membership authenticated via OAuth (Open Authorization) is in early access. Contact support to enable it for your Organization.
- Go to Organization > Member Settings
- Click Invite Member
- Enter the user’s email address
- Click Send Invitation
Removing Members
Admins can remove Members at any time:- Go to Organization > Member Settings
- Find the Member you want to remove
- Click the three-dot menu next to their name
- Select Remove Member
If your Organization uses SSO, a removed Member may be re-provisioned automatically the next time they authenticate through your IdP. To fully revoke access, remove or deactivate the user in your Identity Provider.
Roles
Organizations support two roles: Admin and Member. For a full breakdown of what each role can do across the platform, see Roles & Permissions.Roles and permissions are being progressively rolled out across products and services. Today, the primary distinction is that Admins can manage infrastructure and team membership, while Members can use resources but not modify them. See Roles & Permissions for details.