Invite members, share roles
How to bring people into the company, share permissions with roles and teams, and clean up people who've left.
Under Users & teams › Members in the admin console, you bring people into the company and use roles to decide who can do what.
This page also covers grouping people into teams to grant permissions at once, and cleaning up people who've left.
The invitations here are company member invitations. Inviting users to a specific app happens in Visibility & access.
Getting around the Members screen
The list shows everyone in the company. A search box and two filters sit along the top, with the Invite member button at the far right.
| Column | What it shows |
|---|---|
| Name · Email | Who they are |
| Role | Company admin · Member |
| Team | Which team they're placed in |
| Granted permissions | Access they hold on resources such as connectors |
| Status | Invited · Active · Inactive |
| Last seen | Today · Yesterday · N days ago, or never if they've not signed in |
Companies using AXRouter get one more column: Applied policy.
Search matches names and emails. The filters are status (all, active, inactive) and role. Clicking any row opens that person's detail page.
Inviting members
Invite member at the top right opens the invite dialog. Put one email and one permission (role) per row, and use + to add rows and send several at once.
- Upload file — upload a CSV whose first column is an email and it fills in just the addresses. A file from Google Workspace's Directory › Users › Download users works as-is
- Up to 100 people per batch
- If the same email appears in several rows, the permission from the last row wins
Sent invitations stay in the list as Invited. Click one to see the invite date and expiry; if they haven't joined yet, Resend invitation extends the expiry and Cancel invitation withdraws it.
There are ways in besides invitations. Register a company email domain or turn on directory auto-join, and the people covered by either join just by signing in — see Connect SSO and your directory.
Choosing roles — who can do what
Every member has exactly one role. The role is the scope of what they can do.
| Role | What they can do |
|---|---|
| Company admin | Everything — inviting members, changing roles, removing people, app review, company settings |
| Member | Day-to-day work: building apps, deploying, operating them |
To change one, click into the member and pick from Role on the Basic info tab.
- The last admin's role can't be changed. Promote someone else to admin first
- Lowering your own role locks you out of this screen. You'll get one confirmation prompt
Member management (invites, role changes, removals) requires company admin or above. Without it, the screen won't open at all.
Grouping people into teams
Once there are a lot of people, group them into teams instead of granting permissions one by one. Create one with Create group under Teams in the left menu; a permission granted to a team applies to everyone in it.
The list shows each team's name, headcount, granted permissions, and whether it came from your directory or was made by hand. Click a team to manage three things in one place.
| Tab | What it covers |
|---|---|
| Members | Who belongs to this team |
| Granted permissions | Resources this team may query, such as connectors |
| AI guardrail policy | The AXRouter policy applied to this team (only visible when AXRouter is in use) |
Guardrail policies don't apply immediately. You have to click Save changes at the top right, and leaving before you save raises a warning.
Teams created from your directory
If you connect your company directory, teams are created and filled automatically. These teams carry a Synced badge.
- Moving a synced person to another team by hand unlinks just that person — the badge becomes Manual, and they stop following the directory on the next sync. You'll get a confirmation prompt first
- To undo it, click Re-sync on that person's Basic info tab
Removing members — deactivate first, then delete
Cleanup happens in two steps. Deactivate first, then use Delete from list if you also want them off the roster. The delete button only appears for people who are already inactive — this is deliberate, to prevent accidents.
| Deactivate | Delete from list | |
|---|---|---|
| List | Still shown, as "Inactive" | Gone |
| Access | Blocked — even signing in again won't auto-rejoin them | Blocked — the relationship itself is gone |
| Rejoining | Only by an admin reactivating them | They can come back as a new member via re-invite or auto-join |
| Use when | The goal is blocking (a ban) | The goal is tidying the list (someone who left, a mistaken invite) |
- Deleting also reclaims personal resources issued to that person (AI router keys, dedicated agents, and so on)
- Someone who rejoins after deletion is a new member — their old role and team don't carry over
- You can't deactivate yourself, and the last admin can't be deactivated or deleted. Promote someone else to admin first
- Both removal paths (deactivate and delete) are recorded in the audit log