Skip to main content
Teams use roles for permissions and seat types for usage. The two are independent, with one exception: the Unpaid Admin role always carries the free seat.

Roles

Members are the default role.
  • Full product access through their seat’s included rows
  • Can invite new members (Standard-seat Members only)
  • See the team member table on the Overview tab, without spend columns
  • No access to team settings, billing, or member management
Admins manage the team.
  • Full product access through their seat, plus every admin capability: invite and remove members, change roles and seat types, configure domains and SSO, manage billing and spending controls, view full team analytics
Unpaid Admins manage the team without using a paid seat, for IT, security, or finance staff who never touch the product.
  • Free, not billable
  • Same administrative capabilities as Admins
  • No product access and no included rows
The team owner (whoever created the team) holds a permanent Admin-level role that cannot be changed or removed.

Seat types

Change a seat type

Admins change seat types from the member’s row on the Members tab.
  • Standard to Premium applies immediately; billing prorates for the rest of the cycle.
  • Premium to Standard applies at the next renewal; the member keeps Premium usage until then.

Role comparison

Add a member

Four ways in:
  1. Email invitation. Click Invite Members on the Members tab and enter email addresses. Recipients get an email with an accept link. Invites expire after 7 days and can be revoked from the pending list.
  2. Invite link. Copy the invite link from the invite modal and share it. Joining through the link takes a Standard seat and the Member role.
  3. SSO. Once SSO is configured, users signing in through your identity provider are enrolled automatically.
  4. Domain matching. With a verified domain and domain matching enabled, users whose email matches see a “Join your team” prompt on their own dashboard and join self-serve, as Standard-seat Members.
New members are billed prorated for the remaining days of the cycle at their seat’s rate.
Invite links do not expire on their own, and anyone holding the link can join. Rotate or revoke the link from the invite modal, or control access with domain restrictions or SSO instead.

Remove a member

Admins remove members from the member’s row on the Members tab. On removal:
  • If the member consumed included rows this cycle, the seat stays billed until the end of the billing cycle, then releases. Otherwise the seat releases immediately with a prorated credit on the next invoice.
  • The member’s team-scoped API keys are revoked.
  • Their access tier reverts to whatever they carry personally: a personal subscription if they kept one, free otherwise.
  • Admins can additionally revoke the removed member’s active sessions from the same menu.
A previously removed member who rejoins gets their membership revived rather than duplicated.

Change a role

Admins change roles from the member’s row. Every team keeps at least one Admin and at least one paid member at all times; changes that would violate this are rejected. Moving someone to or from Unpaid Admin also switches them to or from the free seat and adjusts billing from the change date.

Domain settings

Two domain-based controls live in Dashboard → Settings → Domains. Both require at least one verified domain (DNS TXT record; see SSO prerequisites for the record format).

Domain matching

Anyone with a verified, matching email domain can join your team from their own dashboard, no invite needed. Teammates self-serve instead of waiting on an admin.

Restrict invites to verified domains

Invitations to email addresses outside your verified domains are blocked. This prevents accidental or unauthorized additions and keeps membership inside your organization.