Manage team access
See exactly where a person can work, change their role or scope, and remove access safely.
Manage team access
Identity authentication must be enabled to use this page. Organization Admins can manage people within their permitted organization scope. Partner Admins can manage people within their assigned partner and its client portals. Partner Operators and Organization Operators cannot manage team access. Platform Admins can manage access across the platform. Open Admin → Access to invite someone, inspect their current access, or edit an existing membership. If you are unsure which role or sign-in you have, see Sign in with an individual account.
Understand an access row
Each row represents one person's membership in one top-level organization. The Access column shows:
- the person's role;
- the path from the top-level organization to a partner or exact client portal;
- whether coverage is all descendants, selected organizations, or one client portal; and
- the current client portals included in that scope.
Select the client-portal count to see the exact portal names. Future portals included means new portals created below that organization or partner will be included automatically. Staff with access to multiple top-level organizations have a separate row for each one and choose an organization when signing in; staff permissions never combine across organizations. Assign a Client Portal User email in only one organization at a time. If that email already has client access in another organization, remove or reassign the extra access first, or use a separate email for the other organization.
Edit a role or scope
- Select the pencil icon on the membership row.
- Choose the new role and permitted organization, partner, or client portal scope.
- Select Save access.
The top-level organization remains fixed while editing. Staff can receive access to a different top-level organization through Invite or add access with their existing email. Do not use that option to give one Client Portal User email client access in multiple organizations; remove or reassign the extra access first, or use a separate email.
An Organization Admin or Partner Admin can grant only roles and places at or below their own role and already inside their live scope. A Partner Admin can manage team access for the assigned partner and its client portals, but cannot create another partner. The platform checks both the old and new access again when saving. A successful change signs the person out so the updated permissions take effect on their next login.
If someone else changed the row after you opened it, refresh the page and review the latest access before trying again.
Invitation and removal actions
Use the icons in Actions to edit access, resend an invitation, remove one membership from a multi-organization identity, or revoke an identity with one remaining membership. Destructive actions always ask for confirmation.
Removing a membership does not change the person's memberships in other organizations. The final membership cannot be removed this way. A client portal that requires individual accounts must also keep at least one active Client Portal User; change the portal authentication mode before removing or moving its last active client login.