Team members and roles
Invite collaborators, grant appropriate workspace roles, and transfer ownership safely.
Workspace roles control what a member can see and change. Invite each teammate with their own account rather than sharing a login or API key.
Available roles
| Role | Typical access |
|---|---|
| Viewer | View workspace resources and activity without configuration changes |
| Developer | Create and update application resources and perform permitted deployment operations |
| Admin | Developer access plus billing, team administration, backup management, and protected-environment changes |
| Owner | Admin access plus ownership transfer, owner-only member controls, and workspace deletion |
Individual operations can require a higher role. For example, database-backup management requires admin access, and a protected environment restricts changes to admins and owners. A write-scoped API key cannot exceed its creator's role.
Invite a teammate
- Open Workspace settings → Team Members.
- Select Invite members.
- Enter the teammate's email and choose the permitted role.
- Send the invitation.
- Ask the recipient to sign in and verify the matching email address before accepting.
Invitations expire after three days. A pending invitation reserves a member slot until it expires or is revoked. Resend an expired invitation from the dashboard instead of forwarding an obsolete link.
A workspace with a qualifying paid service includes up to ten members. A Free workspace includes one member. See Workspaces.
Who can invite or change roles
Owners and admins can invite developers and viewers. Only an owner can invite an admin or promote someone to admin. An admin cannot remove or change another admin or the owner.
There is no owner role in an ordinary invitation. To change ownership, invite the person, wait for them to become a member, and use the explicit ownership-transfer action.
Remove access
Remove a member in Team Members when they no longer need access. Confirm the correct email address before removal.
Membership checks apply to subsequent authorised requests. Also review credentials that may have been copied outside Openstead, such as third-party API tokens or manually copied database passwords. Removing membership cannot erase a secret already stored elsewhere.
Revoke unused invitations to prevent later acceptance. Invitations are tied to the matching verified email and cannot be used to overwrite an existing member's role.
Transfer ownership
The current owner selects another existing workspace member and confirms their email address. The selected member becomes owner; the previous owner becomes an admin.
Confirm the recipient is the intended person and has working account recovery and two-factor authentication before transferring a production workspace. The owner must transfer ownership before leaving the workspace.
Require two-factor authentication
Qualifying paid workspaces can require members to configure TOTP two-factor authentication. The person enabling the requirement must first enable it on their own account.
Communicate the change to the team and ask members to save recovery codes. See Account security.