Create Teams and Assign Users
Teams are the main access boundary for shared work. Use Users with roles to decide who belongs in the tenant and who can administer it, then use teams to scope agents, workflows, connections, Data, Memory, recordings, and task workspaces. Do not model teams only after the org chart; model them after operational access.
Design Teams Around Risk
Good teams are small enough that every member can safely use the same production resources.
Examples:
Support - Production: can use the support agent, support data, Jira write actions with confirmation, and customer support workflows.Sales Ops - CRM: can use HubSpot and reporting agents, but not finance data.Finance - Reporting: can use finance data collections and read-only reporting workflows.Client A - Delivery: can access client-specific agents, data, and workflows.AI Admins: can edit production agents and review tool execution incidents.
Avoid a single shared team for everyone unless every person should see the same agents and tools.
Create A Team
- Open Teams.
- Click Add Team.
- Enter a clear Name and optional Description.
- Add users who need the same access boundary.
- Submit, then use the team when sharing agents, workflows, connections, Memory, and data.
Use names that explain ownership and purpose. Support - Production is better than Team 1.
User Onboarding Flow
Choose the onboarding method that fits how the organization manages identities. Keep detailed invitation, CSV, and account validation work in Users; use this page to connect identity setup to team access.
| Method | Use when | Detailed instructions |
|---|---|---|
| Create User | An administrator should create an active account immediately. | Creating a new user |
| Invite User | The user should complete registration from an email invitation. | Inviting users |
| Import CSV | Several users should receive invitations in one batch. | Bulk invitation from CSV |
| Approved Domain / SSO | People with an approved company domain should join through configured Google or Microsoft SSO. | Domain-based onboarding |
| Microsoft Entra Sync | Organization groups and their membership are managed from Microsoft Entra ID. | Microsoft Entra synchronization |
Use this order for a controlled rollout:
-
Choose the onboarding method. Decide whether the account will be created, invited, imported, or provisioned through the organization's identity flow.
-
Create or invite the user. In Users, select Create User, Invite User, or Import CSV, or run the configured domain/Entra flow.

-
Assign the least-privileged role. Start with User unless the person needs tenant-wide administration. Use Administrator or Owner only for the responsibilities described in Roles.

-
Add the user to a team. Open Teams, create or edit the correct access boundary, and add the user. Team membership is what connects the account to team-scoped agents, workflows, data, and other shared resources.

-
Verify resource visibility. Ask the user to sign in and confirm that the expected agents and other resources are visible, and that unrelated team resources are not.
-
Review onboarding completion. Check Pending Invites for unaccepted invitations, then confirm that the user has completed registration and appears in the intended team.
Invite → Role → Team → Verify access
Creating an account does not by itself grant access to team-scoped agents or data. The role controls broad platform capabilities; team membership and resource access policies control which shared work the user can reach.
The Users reference above covers invitation behavior, CSV import, approved domains, and pending invitations.
Roles
Use roles for product administration, not day-to-day agent access. Agent, workflow, connection, and data access should normally be controlled through teams and access policies.
| Role | Use for | Avoid using for |
|---|---|---|
| Owner | Organization ownership, security decisions, admin-mode review | Normal power users |
| Administrator | Operational administration, rollout, support, troubleshooting | Users who only need one team of agents |
| User | Standard product usage | Managing tenant-wide settings |
If custom role permissions are used, review them against actual tasks: inviting users, managing roles, creating agents, reviewing feedback, managing connections, and viewing audit data.
Offboarding Checklist
When a user leaves a team or organization:
- Remove the user from teams they no longer need.
- Reassign ownership of production agents, workflows, connections, and API keys.
- Delete or rotate credentials tied to that user's external accounts.
- Review private connections assigned to agents.
- Check Tool Executions for pending approvals owned by the user.
- Confirm SSO or Entra sync will not re-add the user.
Troubleshooting Access
If a user cannot see an agent, workflow, connection, or Memory collection:
- Confirm the user is in the correct organization.
- Confirm the user has the expected role.
- Confirm the team membership.
- Open the resource and check whether it is private, organization-wide, or shared to teams.
- Check whether the team has Can Use or Can Edit/Write access.
- Ask the user to refresh and remove filters before assuming the resource is missing.
Once the pilot membership is correct, define the access policies and visibility rules for its shared resources.