Members
Invite teammates, assign the role each of them holds, connect single sign-on, and govern what AI agents are allowed to do. Every access change is recorded in the audit log.
People
Invite teammates with a copy-link that never depends on email keys, change roles, deprovision or re-enable accounts, and issue password-reset links — the full member lifecycle in-app. Removing the last owner is blocked, and every access change is recorded in the audit log.
Roles & permissions
Roles decide what the people above may do. Composing them — custom roles, field-level restrictions and per-resource scopes — has its own page.
The capability matrix and the role composers live on Roles & permissions. Giving one of those roles to a person happens here, in the list above.
Single sign-on & provisioning
Connect a SAML identity provider, automate user provisioning with SCIM, map identity groups to roles, and verify the domains you enforce SSO on.
AI & agent governance
Verified Mode restricts which capabilities AI and agents may execute. Read access is always auto-approved; write access is granted here, with every action audited.