K

Invite members, share roles

How to bring people into the company, share permissions with roles and teams, and clean up people who've left.

Under Users & teams › Members in the admin console, you bring people into the company and use roles to decide who can do what.
This page also covers grouping people into teams to grant permissions at once, and cleaning up people who've left.

The invitations here are company member invitations. Inviting users to a specific app happens in Visibility & access.

Getting around the Members screen

The list shows everyone in the company. A search box and two filters sit along the top, with the Invite member button at the far right.

ColumnWhat it shows
Name · EmailWho they are
RoleCompany admin · Member
TeamWhich team they're placed in
Granted permissionsAccess they hold on resources such as connectors
StatusInvited · Active · Inactive
Last seenToday · Yesterday · N days ago, or never if they've not signed in

Companies using AXRouter get one more column: Applied policy.

Search matches names and emails. The filters are status (all, active, inactive) and role. Clicking any row opens that person's detail page.

Inviting members

Invite member at the top right opens the invite dialog. Put one email and one permission (role) per row, and use + to add rows and send several at once.

  • Upload file — upload a CSV whose first column is an email and it fills in just the addresses. A file from Google Workspace's Directory › Users › Download users works as-is
  • Up to 100 people per batch
  • If the same email appears in several rows, the permission from the last row wins

Sent invitations stay in the list as Invited. Click one to see the invite date and expiry; if they haven't joined yet, Resend invitation extends the expiry and Cancel invitation withdraws it.

There are ways in besides invitations. Register a company email domain or turn on directory auto-join, and the people covered by either join just by signing in — see Connect SSO and your directory.

Choosing roles — who can do what

Every member has exactly one role. The role is the scope of what they can do.

RoleWhat they can do
Company adminEverything — inviting members, changing roles, removing people, app review, company settings
MemberDay-to-day work: building apps, deploying, operating them

To change one, click into the member and pick from Role on the Basic info tab.

  • The last admin's role can't be changed. Promote someone else to admin first
  • Lowering your own role locks you out of this screen. You'll get one confirmation prompt

Member management (invites, role changes, removals) requires company admin or above. Without it, the screen won't open at all.

Grouping people into teams

Once there are a lot of people, group them into teams instead of granting permissions one by one. Create one with Create group under Teams in the left menu; a permission granted to a team applies to everyone in it.

The list shows each team's name, headcount, granted permissions, and whether it came from your directory or was made by hand. Click a team to manage three things in one place.

TabWhat it covers
MembersWho belongs to this team
Granted permissionsResources this team may query, such as connectors
AI guardrail policyThe AXRouter policy applied to this team (only visible when AXRouter is in use)

Guardrail policies don't apply immediately. You have to click Save changes at the top right, and leaving before you save raises a warning.

Teams created from your directory

If you connect your company directory, teams are created and filled automatically. These teams carry a Synced badge.

  • Moving a synced person to another team by hand unlinks just that person — the badge becomes Manual, and they stop following the directory on the next sync. You'll get a confirmation prompt first
  • To undo it, click Re-sync on that person's Basic info tab

Removing members — deactivate first, then delete

Cleanup happens in two steps. Deactivate first, then use Delete from list if you also want them off the roster. The delete button only appears for people who are already inactive — this is deliberate, to prevent accidents.

DeactivateDelete from list
ListStill shown, as "Inactive"Gone
AccessBlocked — even signing in again won't auto-rejoin themBlocked — the relationship itself is gone
RejoiningOnly by an admin reactivating themThey can come back as a new member via re-invite or auto-join
Use whenThe goal is blocking (a ban)The goal is tidying the list (someone who left, a mistaken invite)
  • Deleting also reclaims personal resources issued to that person (AI router keys, dedicated agents, and so on)
  • Someone who rejoins after deletion is a new member — their old role and team don't carry over
  • You can't deactivate yourself, and the last admin can't be deactivated or deleted. Promote someone else to admin first
  • Both removal paths (deactivate and delete) are recorded in the audit log