# Members, roles, invitations and the activity log

> Invite people to an organization workspace, set their roles, manage seats, and review the organization's activity log.

- Plans: Team, Enterprise
- Canonical: https://docs.devlin.ai/workspace-and-team/members-and-roles

An organization workspace is shared by its members, and each member has a role: owner, admin or member. Owners and admins invite people, remove them and review the activity log from the organization's settings. Inviting people needs an organization on the Team, Enterprise plans.

## Before you start
- Switch to the organization workspace. Its settings only open while the organization is your active workspace. See [Workspaces](https://docs.devlin.ai/workspace-and-team/workspaces).
- You need to be the owner or an admin. Members do not get the organization's settings sections: for them the settings rail lists only **Plans** and **Credits & Billing** under the organization's name.
- Check that a seat is free, or be ready to add one. See the Seats section below.
- Know the email address the person signs in with. An invitation can only be accepted by an account with the invited email address.

## Roles
Every organization has one owner. Everyone else is an admin or a member.

- **Owner**: does everything an admin can, and is the only role that can invite admins, change a person's role, remove admins, transfer ownership, and open the **Subscription** section of the organization's settings.
- **Admin**: opens the organization's settings, invites members, revokes invitations, removes members, and reads the activity log. An admin cannot invite or remove another admin, and cannot change anyone's role.
- **Member**: has no access to the organization's **Members** or **Activity** sections.

## Steps
1. Open Settings and select **Members** in the rail under your organization's name.
2. Under **Send an invitation via email**, enter the person's email address.
3. Choose a **Role**: **Member** or **Admin**. Only the owner can invite an admin, so an admin sees only **Member** in the menu.
4. Select **Send invite**.
5. If the organization is out of seats on a Team subscription billed through Stripe, a dialog shows the price of another seat. Select **Add seat and send invite** to buy the seat and send the invitation, or **Cancel** to send nothing.

## Result
The page shows **Invitation sent** with a **Copy invite link** button for a few seconds, and the invitation appears under **Pending invitations** with its role and expiry date. devlin.ai emails the person a link to the invitation. If the email does not arrive, use **Copy link** on the pending invitation and send the link yourself.

If the address already belongs to a member of the organization, or already has an invitation in the list (pending or expired), the invitation is refused with "An invitation could not be created for this email." The message is the same in both cases. For an expired invitation, use **Resend invite** or revoke it first.

There is an hourly limit on how many invitations an organization can send. Past it you see "Too many invitations. Please try again later."

## Invitation expiry, resending and revoking
An invitation is valid for 7 days from the moment it is sent. After that the link stops working, and the invitation no longer holds a seat.

- An expired invitation stays in the **Pending invitations** list with an **Expired** badge and a **Resend invite** button. Once it has been expired for more than 30 days it is removed from the list.
- **Resend invite** creates a new link, emails it, and makes the invitation valid for another 7 days. Links from earlier emails stop working. Only the owner can resend an invitation for the admin role. Resending an expired invitation takes a seat again, so it is checked against the seat limit like a new invitation. Resending never buys a seat: on a Team subscription with no free seat you see "Your team is out of seats. Remove a member or another pending invitation, or revoke this invitation and send a new invite to add a seat."
- To revoke, select **Revoke** on an invitation, then **Revoke invitation** to confirm. The invitation is deleted and its link stops working immediately. Owners and admins can revoke any invitation that has not been accepted.
- If the person you invited changes their devlin.ai sign-in email before accepting, the invitation is cancelled: it leaves the list, frees its seat, and its link stops working. Send a new invitation to their new address.

## Accepting an invitation
The link in the email opens the invitation page. What the invited person sees depends on the state of the invitation and of their sign-in.

- Not signed in: the page names the organization and the role, with a **Sign in to join** button. After signing in, the person is brought back to the invitation.
- Signed in with the invited email address: the page shows an **Accept invitation** button. Accepting adds the person to the organization with the invited role, makes the organization their active workspace, and opens the dashboard.
- Signed in with a different email address: the page shows **Signed in as a different account** and a **Sign out and switch** button, which signs the person out and opens sign-in so they can use the invited address. Upper and lower case in the address do not matter. The page does not reveal which address was invited.
- Already a member: someone who is signed in with the invited address and already belongs to the organization is sent to the dashboard.
- Invalid link: the page shows **Invalid invitation** with a **Go to dashboard** button when the link is unknown, has expired, was revoked, was replaced by a resend, or was already accepted. Ask an owner or admin for a new invitation.

Accepting can still be refused:
- If the organization's seats were reduced after the invitation was sent and every seat is now filled by a member, the person is not added and is told that no seat is available.
- If single sign-on is required for the person's email domain and they signed in another way, they see "Your organization requires single sign-on. Sign in through your organization's SSO, then open this invitation again." See [SAML SSO and multi-factor authentication](https://docs.devlin.ai/workspace-and-team/sso-and-mfa).

People who sign in through an organization's SAML SSO connection are added to that organization at sign-in, without an invitation.

## Change a role
Only the owner can change roles. In **Active members**, use the role menu on a person's row to switch between **Admin** and **Member**. The change applies as soon as you pick it, with no confirmation. The owner's own row shows **Owner** and has no menu. To make someone else the owner, transfer ownership.

## Remove a member
In **Active members**, select **Remove** on the person's row, then **Remove** in the **Remove member** dialog. Their membership is deleted and they lose access to the organization immediately.

- The owner can remove admins and members.
- An admin can remove members. Admins do not see **Remove** on the rows of other admins or on their own row.
- The owner cannot be removed. Transfer ownership first.

A member or admin can also leave on their own from **Settings → Workspaces**, under **Organizations you belong to**. See [Leave an organization](https://docs.devlin.ai/workspace-and-team/workspaces#leave-an-organization).

## Transfer ownership
Only the owner can transfer ownership, and only to someone who is already a member of the organization.

1. In **Active members**, select **Make owner** on the person's row.
2. In the **Transfer ownership** dialog, select **Transfer ownership**.

The person becomes the owner and you become an admin. The organization's billing contact email changes to the new owner's address. You are then taken to the dashboard. The transfer cannot be undone by you: only the new owner can transfer ownership back.

## Seats
A seat is used by every member of the organization, including the owner, and by every invitation that is still valid. Expired invitations do not use a seat. What happens when you run out depends on the plan.

### Seats on a subscription
This applies to organizations on the Team plan.

- The plan includes 5 seats and can grow to 15. Members and valid invitations together can never exceed 15. Past that, the invitation is refused and the message points you to the Enterprise plan.
- Custom seat counts: if devlin.ai has set a seat count for your organization, that count is the limit instead. An invitation past it is refused with a message that names the limit and asks you to contact us. Up to that count, a subscription billed through Stripe still buys each seat past the ones it already has.
- The top of the **Members** section shows how many seats are used out of the seats on the subscription, with the number of pending invitations in brackets, and either the seats remaining or the notice "Sending another invite will add a seat to your subscription."
- Adding a seat: there is no separate control for buying seats. When every seat is used, sending an invitation opens a dialog with the price of a seat for the subscription's billing cycle (per month, or per year on an annual subscription). Confirming with **Add seat and send invite** adds a seat to the Stripe subscription, charges a prorated amount for the rest of the current billing cycle, and sends the invitation. Owners and admins can both do this.
- Releasing a seat: when you remove a member, when a member or admin leaves the organization, when you revoke an invitation, and when an invitation expires, seats beyond the included 5 that are no longer needed are taken off the subscription. Expired invitations are checked once a day.
- Invoiced subscriptions: if your Team plan is billed by invoice instead of through Stripe, no seat can be bought from the **Members** section: an invitation sent when every seat is used is refused with "Your plan's seats are managed on your agreement. Contact us to add seats." If devlin.ai has set a seat count for your organization, you can invite up to that count.
- The owner sees the current seat count in the **Subscription** section. On a subscription billed through Stripe, its **Manage Subscription** button opens the Stripe customer portal for billing, payment method and invoices.

### Seats set by agreement
On the Enterprise plan, the number of seats is set by your devlin.ai agreement. You can invite people while members and valid invitations together are below that number. If no number is set for your organization, invitations are not limited by seats. At the limit, an invitation is refused with a message that states the limit, and you remove a member or a pending invitation or contact devlin.ai to add seats. The **Members** section does not show a seat counter on this plan. The owner sees the seat count in the **Subscription** section.

### Organizations without a subscription
An organization on the Free plan has a seat limit of 1, and the owner counts toward it, so invitations are refused until the organization is on one of the Team, Enterprise plans. The owner upgrades from **Plans** in the settings rail.

### Asking the owner to upgrade
Admins cannot change the organization's plan or billing. In their place, while the organization is on neither Team nor Enterprise, an admin sees a **Request upgrade from owner** button on the Team plan card under **Plans**. Once the organization is on one of those plans, the card shows "Billing is managed by the workspace owner." instead. The button emails the owner with the organization's name and the admin's name and email address, and shows "Request sent to the workspace owner." Members do not get this button.

## The activity log
Owners and admins can open **Activity** in the settings rail to see changes to the organization, newest first. Each entry shows what happened, the email address of the person who did it (or "System" when there is none), and the date and time. The list loads a page at a time. Select **Load more** for older entries.

The log records:
- The organization being created, and changes to its name or URL.
- Invitations sent, resent and revoked.
- Members joining, leaving, being removed, and having their role changed.
- Ownership transfers.
- A simulation being transferred into or out of the workspace.
- Learner identity collection being turned on or off, and changes to where it applies.
- Power BI export API keys being created and revoked.
- MCP activity: the MCP server being turned on or off, access tokens created and revoked, changes applied by an AI tool, and changes to live content that were requested, approved or denied.

Email addresses are stored with each entry, so an entry stays readable after the person leaves the organization. The log is read-only, and it cannot be searched, filtered or exported from the app.

## AI tools over MCP
An AI tool connected through the [MCP server](https://docs.devlin.ai/integrations/mcp-server-and-ai-tool-connectors) cannot invite or remove people, change roles, transfer ownership or buy seats. Those actions are made by a person in Settings.

## Related
- [Workspaces](https://docs.devlin.ai/workspace-and-team/workspaces)
- [SAML SSO and multi-factor authentication](https://docs.devlin.ai/workspace-and-team/sso-and-mfa)
- [Your account: profile, email, theme, digest and deleting your account](https://docs.devlin.ai/workspace-and-team/account-settings)
- [Data privacy, retention and learner data requests](https://docs.devlin.ai/workspace-and-team/data-privacy-and-retention)
- [MCP server and AI tool connectors](https://docs.devlin.ai/integrations/mcp-server-and-ai-tool-connectors)
- [Plan availability](https://docs.devlin.ai/reference/plan-availability)
