Invite your team

Members and roles are what the Team plan adds.

Inviting

Roles and permissions is what you are handing over, organizations and teams is the container, notifications is what they will hear about, and plans and pricing is what a seat costs.

By email. They sign in passwordlessly, the same way you did — there is no password to set and none to reset.

What a new member gets

Access to the organization’s connections, bounded by their role in the UI and by the connection’s scopes on your Worker.

Not a credential of their own. The connection’s keypair belongs to the organization, and adding a person does not mint a second one.

What the record shows

Every administrative action carries the dashboard user’s own subject, alongside the connection id.

So a shared credential still distinguishes who acted — which is exactly the property a team needs and a single-user account does not.

A shared record of who did what, and when is one of the four things the Team plan is for.

Removing somebody

Revoking their dashboard access does not revoke the credential your Worker trusts.

Two separate acts, deliberately. The connection belongs to the organization, so somebody leaving does not take it with them — and if you want the credential rotated as well, that is rotate and revoke.

The one rule worth agreeing on first

Who may grant an entitlement.

Grant mints paid product out of nothing. It is the action most worth restricting, and it is a separate scope from revoke precisely so a refund tool never has it.

Notifications fan out

Security and release notifications reach one person on Solo, and a team on Team.

Scheduled checks against your Workers are the other half — and both are about the same thing: somebody finding out before a customer does.

What we store about your team

Our own users and organizations. Their names, their addresses, their roles.

Not your users. Yours live in your D1 and are fetched live.

ESC