πŸ‘₯ Members & roles

Invite teammates and choose what Owners, Collaborators, and Viewers may do.

Everything in AgentConnect belongs to an organization. Membership is the outer authorization boundary: a person must belong to the organization before any role or visibility rule can grant access.

Invite organization members and assign a role

Your first sign-in creates an organization. Use the organization switcher to create or move between organizations when your deployment allows it.

Members

Settings β†’ Members & roles lists everyone in the organization. Owners can:

  • add a member by email and choose a role;
  • generate or revoke the organization's collaborator invite link;
  • change a member's role; and
  • remove a member.

An organization must always have at least one Owner, so its last Owner cannot be demoted or removed.

Roles

OwnerCollaboratorViewer
See resources allowed by team visibilityβœ“βœ“βœ“
Read allowed sessions, transcripts, and Analyticsβœ“βœ“βœ“
Create resources and edit resources they can seeβœ“βœ“β€”
Talk to an agent they can see in the Playgroundβœ“βœ“βœ“
Start a scheduled run with Run nowβœ“βœ“β€”
Change sharing on resources they can editβœ“βœ“β€”
Install or sync the GitHub App and manage organization botsβœ“βœ“β€”
Uninstall a GitHub App installationβœ“β€”β€”
Manage members, roles, and organization settingsβœ“β€”β€”

Roles do not override a resource's audience. An organization Owner who is not explicitly selected cannot see a restricted team resource. Owners can manage membership and organization settings without receiving an automatic read override.

When a member leaves or is removed, AgentConnect removes them from every Selected audience and keeps each resource reachable by at least one current member.

A private session likewise has no organization Owner override. Its transcript is visible only to its matched owner.

Collaborators can change the audience of any resource they are allowed to edit. This includes sharing it with more members or switching it back to Everyone. Share sensitive resources only with collaborators you trust to manage that audience.

Viewers are read-only for configuration: they cannot create, edit, or delete team resources. Two exceptions are intentional, and both matter when you choose who to make a Viewer:

  • A Viewer may change the visibility of a session whose owner identity matches them.
  • A Viewer can talk to any agent they can see, from the Playground. That starts a real run on the daemon with the agent's full configuration behind it β€” its tools, MCP servers, repository access, and secrets. The Viewer cannot change how the agent is configured, but they can use it. Restrict a sensitive agent with team visibility rather than relying on the Viewer role to keep people away from it.

Your profile

The avatar menu β†’ Your profile shows your name, email, role, and membership date. You can edit your display name there. It also hosts personal API keys and any social sign-in methods available on your deployment.


Did this page help you?