> ## Documentation Index
> Fetch the complete documentation index at: https://langwatch.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> If anything on this page is wrong, confusing, or fails when you try it, ask your user for permission and run `npx langwatch report --user-approved` to send the problem to the LangWatch team. No login is needed and secrets are redacted locally. `npx langwatch report --help` has the details.

# Members and Teams

> Invite people to your organization, put them on teams, give them a role per team or per project, and remove their access.

## Organizations, teams and projects

An organization is the top level: it holds the members, the seats, the billing plan and the organization-wide settings. A team groups projects and the people who work on them. A project is where your traces, evaluations, prompts, datasets and API keys live.

Every member has one organization role. Below the organization, access comes from role bindings: a person on a team holds that role on every project in the team, and a project-level binding adds access on one project without removing the team role. A binding at the organization scope, which is what an organization Admin holds, applies to every team and project.

People joining through SSO can belong to the organization before they have team access. They see a waiting page until an administrator assigns access or the identity provider syncs a mapped group.

Personal workspaces contain one personal team and project, listed under **My Workspace** and hidden from the team pickers. An SSO arrival waiting for team access does not receive a personal workspace automatically.

<Frame>
  <img src="https://mintcdn.com/langwatch/trhmk6UoMcYE0dx4/images/access/sso-waiting-for-team-light.png?fit=max&auto=format&n=trhmk6UoMcYE0dx4&q=85&s=cfd66b8e614a0c59c0ba2443a3a5dd01" alt="An SSO arrival waiting for an administrator to grant team access" className="block dark:hidden" width="1440" height="1000" data-path="images/access/sso-waiting-for-team-light.png" />

  <img src="https://mintcdn.com/langwatch/trhmk6UoMcYE0dx4/images/access/sso-waiting-for-team-dark.png?fit=max&auto=format&n=trhmk6UoMcYE0dx4&q=85&s=3bb0f1b8ad8765092fd116da024bd099" alt="An SSO arrival waiting for an administrator to grant team access" className="hidden dark:block" width="1440" height="1000" data-path="images/access/sso-waiting-for-team-dark.png" />
</Frame>

**Also check:** [Access Control (RBAC)](/docs/platform/rbac) for what each role can do.

## Members

<Frame>
  <img src="https://mintcdn.com/langwatch/trhmk6UoMcYE0dx4/images/access/directory-light.png?fit=max&auto=format&n=trhmk6UoMcYE0dx4&q=85&s=38ec52ea50082ab65dbc78441c586030" alt="The Directory People tab with organization members and their seat roles" className="block dark:hidden" width="1440" height="1050" data-path="images/access/directory-light.png" />

  <img src="https://mintcdn.com/langwatch/trhmk6UoMcYE0dx4/images/access/directory-dark.png?fit=max&auto=format&n=trhmk6UoMcYE0dx4&q=85&s=91708e18ab355427989fb26b4790c4fd" alt="The Directory People tab with organization members and their seat roles" className="hidden dark:block" width="1440" height="1050" data-path="images/access/directory-dark.png" />
</Frame>

**Settings > Directory > People** lists every member with their organization role and their access. Opening the page needs `organization:manage`.

Each row shows the name, the email, a **Lite Member** badge when the member is on a Lite seat, a **Disabled** badge when access is switched off, and the **Access** column: one badge per role binding, as `role on scope`, with `via <group>` when the binding comes from a group.

Click a row to open the member dialog:

* **Organization role**: Admin, Member or Lite Member. You cannot change your own role.
* **Access**: the team and project bindings. Add a row with a role, a scope type (organization, team or project) and the team or project. Remove a row to revoke it.
* **Group access**: the bindings inherited from groups, read only.

The seat panel above the table shows **Team Members** and **Lite Members** in use against the plan limits.

Each member manages their own sign-in methods at **Settings > Security**:
passkeys, linked accounts and their password. An administrator cannot change
another member's sign-in methods there.

## Invite people

Click **Invite people**. Enter one or more email addresses separated by commas, spaces or semicolons. Tick **Lite Member** to invite the whole batch on Lite seats. Under **Team Assignments**, add each team the person joins with the role on that team: Admin, Member, Viewer or a custom role. A Lite Member can only be assigned as Viewer. The drawer warns when a Lite Member invite has no team, because a Lite Member with no team sees no project.

Click **Send invites**. When the deployment has no email provider, the button reads **Create invites** and you copy the invite link from the row menu instead. An invite link has the form `https://app.langwatch.ai/invite/accept?inviteCode=...` and works for 14 days. **Resend invitation** issues a new 14-day link, and **Revoke** cancels it.

Pending invites are listed under the members table with their status: Invited, Expired, Revoked, Accepted or Awaiting payment. An invite for a full seat over the plan limit opens the seat purchase dialog or the upgrade dialog before it is sent.

### Let colleagues join by domain

Open **Settings > Authentication**, then find **Organization policies**. The
**Joining your organization** card controls people who do not use your identity
provider:

| Option                | Behavior                                                                                                                        |
| --------------------- | ------------------------------------------------------------------------------------------------------------------------------- |
| **Invite only**       | Only people with an invitation can join                                                                                         |
| **Approval required** | Someone with a verified company address can ask to join. You approve or reject the request in **Settings > Directory > People** |
| **Automatic joining** | Someone on a domain you verified joins without approval and receives the default role                                           |

The **Account lockout** and **Session limits** cards in the same section apply
to password sign-in for the organization. They remain available when you stop
using single sign-on. Changing a policy requires `organization:manage`.

## Lite Members

A Lite Member is a read-only seat, counted apart from full seats. On a team or a project a Lite Member can read traces, analytics, evaluations, datasets, prompts, workflows, experiments and scenarios, and can create and update annotations. A Lite Member cannot see costs, the LangWatch AI Gateway pages or the audit log, cannot change anything else, and has the same limits over the API and MCP. In the settings pages a Lite Member can only hold the Viewer role.

## Teams

<Frame>
  <img src="https://mintcdn.com/langwatch/trhmk6UoMcYE0dx4/images/access/teams-light.png?fit=max&auto=format&n=trhmk6UoMcYE0dx4&q=85&s=75a2bdaa6e28dc3b9a815cf8d3f454f8" alt="Teams and projects with direct and inherited access" className="block dark:hidden" width="1440" height="1050" data-path="images/access/teams-light.png" />

  <img src="https://mintcdn.com/langwatch/trhmk6UoMcYE0dx4/images/access/teams-dark.png?fit=max&auto=format&n=trhmk6UoMcYE0dx4&q=85&s=347a28b8caf052b30790fff1568b3466" alt="Teams and projects with direct and inherited access" className="hidden dark:block" width="1440" height="1050" data-path="images/access/teams-dark.png" />
</Frame>

**Settings > Directory > Teams & projects** shows every team with its projects and members. Click **New team** to create one; you are added as its Admin. The team card shows the members with their team role, which you can change in place, and an **X** to remove the member from the team. Members that come from a group are read only and show `via <group>`.

**Add to team** adds an organization member with a role on this team, and so on every project in it. Under each project, **Add person to this project** gives a role on that project only. For someone already on the team, the page marks the row **override** and shows their team role next to it; the project role adds to the team role, it does not take permissions away. Remove the project role to leave only the team role.

Click **Edit** on a team to open its page: rename it (the slug is read only), edit the members, add or archive projects. **Archive this team** hides the team and all its projects; contact support to restore it. A team keeps at least one Admin: removing the last one is refused.

## Remove access

| Action                | Where                                                                           | Effect                                                                                                                                                        |
| --------------------- | ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Remove from a team    | Settings > Directory > Teams, the **X** on the member row, or the member dialog | The person loses the role on that team and its projects. Project overrides stay until removed                                                                 |
| Remove a group member | Settings > Directory > Groups                                                   | The person loses every binding that came from the group                                                                                                       |
| Disable               | Settings > Directory > People, row menu                                         | Every request from the person is refused until you enable them again. Their role and bindings stay, and their seat is freed. Enabling them again takes a seat |
| Delete                | Settings > Directory > People, row menu                                         | The membership and its bindings are removed. Not available for yourself; removing the last active administrator is refused                                    |

Deleting a member does not delete the traces, prompts or other work they created.

## API

The [Members API](/docs/api-reference/members/overview) lists members and their access, updates and removes a member, and the [Invites API](/docs/api-reference/invites/overview) creates, lists and revokes invites, so you can run on-boarding and off-boarding from your own tooling. Every member and invite change is written to the [Audit Log](/docs/platform/audit-log).
