Members & access
Who is in your organization, what role they hold, and who is allowed to join.
Who can do what
| Task | User | Agent owner | Admin |
|---|---|---|---|
| See the member list | — | — | ✅ |
| Add a member | — | — | ✅ |
| Edit a member's name or email | — | — | ✅ |
| Grant or remove admin | — | — | ✅ |
| Remove a member | — | — | ✅ |
| Manage the allowed-accounts list | — | — | ✅ |
Organization → Users.
Adding a member
Add someone by name and email. If they already have a Delegate account, they're attached to your organization; if not, one is created for them. Either way their role is per-organization, so someone who is an Admin elsewhere joins yours as a User unless you say otherwise.
Agents can add members too, with the invite_user tool — useful when an agent
is running an onboarding process.
Roles
User or Admin, changeable at any time. Remove Admin demotes without removing access. See Who can do what.
Inside an organization, groups add a third, narrower role: a group admin manages one group's members and agents without being an admin of the whole organization.
Keep more than one admin. Admin-only capabilities — billing, budgets, connections, share links — have no other route, and an organization whose single admin leaves needs support intervention to recover.
Allowed accounts
The Allowed Accounts list controls which email addresses may join at all. It's the gate in front of the member list: useful for keeping an organization to your own domain, or to a named set of collaborators.
Removing someone
Removing a member ends their access immediately and takes them out of every group in the organization. Two things to do first, because they're harder afterwards:
- Move their agents. Agents they own don't move on their own. Use Transfer Ownership to hand each to someone who will keep it running — this matters most for agents with routines, which otherwise keep running under a departed owner.
- Revoke their API keys. An admin can revoke all of a user's keys in one action.
Removal is a soft delete: the person's history and their agents' work stay intact, so cost records and session history remain correct.
What admins can see
An admin can open every agent in the organization, including agents that were never shared with them, and read their sessions and files. There is no private-from-admin agent. Say so plainly when people ask — it's better known up front than discovered.