Skip to main content

Create Teams and Assign Users

Teams are the main access boundary for shared work. Use Users with roles to decide who belongs in the tenant and who can administer it, then use teams to scope agents, workflows, connections, Data, Memory, recordings, and task workspaces. Do not model teams only after the org chart; model them after operational access.

Design Teams Around Risk

Good teams are small enough that every member can safely use the same production resources.

Examples:

  • Support - Production: can use the support agent, support data, Jira write actions with confirmation, and customer support workflows.
  • Sales Ops - CRM: can use HubSpot and reporting agents, but not finance data.
  • Finance - Reporting: can use finance data collections and read-only reporting workflows.
  • Client A - Delivery: can access client-specific agents, data, and workflows.
  • AI Admins: can edit production agents and review tool execution incidents.

Avoid a single shared team for everyone unless every person should see the same agents and tools.

Create A Team

  1. Open Teams.
  2. Click Add Team.
  3. Enter a clear Name and optional Description.
  4. Add users who need the same access boundary.
  5. Submit, then use the team when sharing agents, workflows, connections, Memory, and data.

Use names that explain ownership and purpose. Support - Production is better than Team 1.

User Onboarding Flow

Choose the onboarding method that fits how the organization manages identities. Keep detailed invitation, CSV, and account validation work in Users; use this page to connect identity setup to team access.

MethodUse whenDetailed instructions
Create UserAn administrator should create an active account immediately.Creating a new user
Invite UserThe user should complete registration from an email invitation.Inviting users
Import CSVSeveral users should receive invitations in one batch.Bulk invitation from CSV
Approved Domain / SSOPeople with an approved company domain should join through configured Google or Microsoft SSO.Domain-based onboarding
Microsoft Entra SyncOrganization groups and their membership are managed from Microsoft Entra ID.Microsoft Entra synchronization

Use this order for a controlled rollout:

  1. Choose the onboarding method. Decide whether the account will be created, invited, imported, or provisioned through the organization's identity flow.

  2. Create or invite the user. In Users, select Create User, Invite User, or Import CSV, or run the configured domain/Entra flow.

    Create User form with identity, contact, and password fields

  3. Assign the least-privileged role. Start with User unless the person needs tenant-wide administration. Use Administrator or Owner only for the responsibilities described in Roles.

    Assign Role dialog with Owner, Admin, and User options

  4. Add the user to a team. Open Teams, create or edit the correct access boundary, and add the user. Team membership is what connects the account to team-scoped agents, workflows, data, and other shared resources.

    Team creation form with a user selected for membership

  5. Verify resource visibility. Ask the user to sign in and confirm that the expected agents and other resources are visible, and that unrelated team resources are not.

  6. Review onboarding completion. Check Pending Invites for unaccepted invitations, then confirm that the user has completed registration and appears in the intended team.

Invite → Role → Team → Verify access

Creating an account does not by itself grant access to team-scoped agents or data. The role controls broad platform capabilities; team membership and resource access policies control which shared work the user can reach.

User administration reference

The Users reference above covers invitation behavior, CSV import, approved domains, and pending invitations.

Roles

Use roles for product administration, not day-to-day agent access. Agent, workflow, connection, and data access should normally be controlled through teams and access policies.

RoleUse forAvoid using for
OwnerOrganization ownership, security decisions, admin-mode reviewNormal power users
AdministratorOperational administration, rollout, support, troubleshootingUsers who only need one team of agents
UserStandard product usageManaging tenant-wide settings

If custom role permissions are used, review them against actual tasks: inviting users, managing roles, creating agents, reviewing feedback, managing connections, and viewing audit data.

Offboarding Checklist

When a user leaves a team or organization:

  • Remove the user from teams they no longer need.
  • Reassign ownership of production agents, workflows, connections, and API keys.
  • Delete or rotate credentials tied to that user's external accounts.
  • Review private connections assigned to agents.
  • Check Tool Executions for pending approvals owned by the user.
  • Confirm SSO or Entra sync will not re-add the user.

Troubleshooting Access

If a user cannot see an agent, workflow, connection, or Memory collection:

  1. Confirm the user is in the correct organization.
  2. Confirm the user has the expected role.
  3. Confirm the team membership.
  4. Open the resource and check whether it is private, organization-wide, or shared to teams.
  5. Check whether the team has Can Use or Can Edit/Write access.
  6. Ask the user to refresh and remove filters before assuming the resource is missing.

Once the pilot membership is correct, define the access policies and visibility rules for its shared resources.