> ## Documentation Index
> Fetch the complete documentation index at: https://docs.switchagents.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs moved from docs.flintai.dev to docs.switchagents.ai. Use docs.switchagents.ai for every link and request.
> To search these docs from an AI tool, connect the MCP server at https://docs.switchagents.ai/mcp. The page index is at https://docs.switchagents.ai/llms.txt.

# Users

> Invite people to your Switch Trust organization and manage their roles

The **Users** page is where you invite people to your organization, see who already has
access, and control what each person can do through their role.

To open it, select the **Settings** icon <svg width="18" height="18" viewBox="0 0 24 24" fill="none" stroke="currentColor" strokeWidth={2} strokeLinecap="round" strokeLinejoin="round" style={{ display: "inline", verticalAlign: "text-bottom", margin: 0 }} aria-label="Settings"><path d="M20 7h-9" /><path d="M14 17H5" /><circle cx="17" cy="17" r="3" /><circle cx="7" cy="7" r="3" /></svg> in Switch Trust, then under **Admin** select **Users**.

## The users list

The list shows everyone with access to your organization, one per row. Use the search box to
filter the list, and the **Columns** control to show or hide columns.

Each row has these columns:

* **User** is the person's name and email. Your own row is marked **(you)**.
* **Role** is the role they hold, which decides what they can do. See
  [Roles and permissions](#roles-and-permissions).
* **Status** is where they are in the invitation flow:
  * **Active** means they've accepted and have access.
  * **Pending** means they've been invited but haven't accepted yet.
  * **Expired** means their invitation lapsed before they accepted.
  * **Revoked** means their invitation was withdrawn.
* The last column is the **...** actions menu, where you can [change a role](#change-a-role)
  or [remove a user or revoke an invitation](#remove-a-user-or-revoke-an-invitation).

## Roles and permissions

Every member holds one role, and the role decides what they can see and change. Assign the
least access that lets someone do their job.

| Role | What it can do |
| - | - |
| **Org Admin** | Full control, including billing, members, roles, settings, global guardrails, and transferring or deleting the organization. |
| **Admin** | Manage members, data sources, scans, guardrails, evaluations, and organization settings. Can't manage billing or delete the organization. |
| **Editor** | Read and write on agent workflows, such as connecting repositories, running scans and evaluations, setting guardrails, and managing their own API keys. Can't manage members, billing, or settings. |
| **Viewer** | Read-only everywhere, including inventory, findings, scores, and reports. Can't make changes. |

## Invite a user

<Steps>
  <Step title="Open the invite dialog">
    On the **Users** page, select **Invite user**.
  </Step>

  <Step title="Enter their email and role">
    Enter the person's **Email address**, then choose the **Role** to give them. Pick the
    role that matches what they need to do (see [Roles and permissions](#roles-and-permissions)).
    You can only grant a role up to your own, so an **Admin** can't invite someone as an
    **Org Admin**.
  </Step>

  <Step title="Send the invitation">
    Select **Send**. The person gets an email invitation and appears in the list as
    **Pending** until they accept.
  </Step>
</Steps>

## Change a role

To change what someone can do, open the actions menu on their row and select **Change role**,
then pick the new role and select **Save**.

A few limits apply, so that no one can grant access beyond their own or lock the organization
out of admin control:

* You can only assign a role up to your own. The roles you can't grant don't appear as choices.
* You can't manage a member who outranks you. Their row has no actions menu.
* You can't change your own role, and the same goes for removing yourself.
* The organization always keeps at least one **Org Admin**.

<Warning>
  Lowering someone's role immediately and permanently revokes any of their API keys scoped
  above the new role. Revoked keys can't be restored, so the member has to create new ones.
</Warning>

## Remove a user or revoke an invitation

Open the actions menu on a person's row:

* For a member who has accepted, select **Remove from organization**. They lose access right
  away, and this can't be undone.
* For someone still **Pending**, select **Revoke invitation** to withdraw it before they
  accept. This can't be undone either, but you can invite them again later.

<Note>
  Managing members is limited to the **Admin** and **Org Admin** roles. A **Viewer** or
  **Editor** can see the list but can't invite, remove, or change anyone.
</Note>
