Team Management
Invite trusted workspace members, change displayed roles, switch workspaces, and understand the current authorization boundary.
Choose the workspace before changing shared data
Diem calls a workspace an Account in parts of the system. The workspace selector creates, restores, and switches the active account. Most shared requests include that active account, but some personal surfaces do not.
Invite a trusted member
Open Team
Confirm the workspace name shown at the top of the page.
Choose Invite Member
Owners and admins can open the invitation dialog in the current UI.
Enter email and a role label
Choose Admin, Member, or Viewer, then send the invitation.
Have the recipient accept
The recipient opens the invitation link, signs in with the invited email, and joins the selected workspace.
Verify membership
Confirm the member shows Active rather than Pending before relying on their access.
Displayed role labels
| Role | Current interface meaning |
|---|---|
| Owner | Workspace owner; cannot be changed or removed by the standard Team controls. |
| Admin | Shown as having broad management access and can see member controls in the UI. |
| Member | Shown as a content collaborator. |
| Viewer | Shown as read-only in the UI, but this is not a reliable backend guarantee. |
Owners and admins see role and removal controls for non-owners. When removing a member, confirm that the correct workspace and person are selected.
Current team security limitations
- Remove access promptly when a person leaves the team.
- Review connected providers and Stripe separately; team removal does not rotate third-party credentials.
- Check personal Link Page, Profile, and Settings data after account switching.
- Contact support if a removed member appears to retain access.