# Users, teams and roles

People join an organization by invitation, and reach workspaces through teams. The rules behind roles and access are in [Access model](/concepts/access-model).

## Before you start

- Inviting, changing roles, suspending and removing people needs the Owner organization role.
- Creating teams, managing their members and granting them workspace access needs the Owner organization role.

## Invite people

1. Open **Settings**, then **Users**, and select **Invite User**.
2. Enter the **Email Address**, **First name** and **Last name**.
3. Choose a **Role**: Integration Owner, Editor or Viewer.
4. Select **Send Invitation**.

The person is listed as Invited until they accept, and the list shows when the invitation expires. **Resend invite** sends it again. The Owner role cannot be given by invitation.

## Change a role, suspend or remove

Open a person's actions on **Settings**, then **Users**:

- **Change Role** sets their organization role.
- **Suspend** takes their access away until **Reactivate**.
- **Remove** takes them out of the organization.

## Create a team

1. Open **Settings**, then **Teams**, and select **New Team**.
2. Enter a **Team Name** and create it.

Every organization also has the system team Everyone; see [Access model](/concepts/access-model).

## Add members

Open the team. Under **Members**, select **Add member**, choose the person and their team role: Owner, Editor or Viewer. Change a member's team role in the list, or remove them from the team; they keep their organization membership and lose only what this team grants.

## Grant workspace access

Under **Workspace Access** on the team, select **Grant access**, choose the workspace and the level: No access, Can view or Can edit. Change the level in the list, or remove the access.

## Delete a team

Choose **Delete Team** on the team. Its members keep their organization membership.

## Related

- [Access model](/concepts/access-model)
- [Sign-in and security](/admin/sign-in-security)
