# Inviting your team

**You'll need:** an administrative role. If **Administration** is missing from the
bottom of your sidebar, you do not have it yet.

## Add someone

**Administration → Users → Create user.** Enter their name and email address and pick
their roles at the same time. They receive an email invitation, and their account is
created when they accept it.

The email address does not have to be on your domain. Contractors, agencies and
photographers are ordinary members with narrow roles.

## Choose roles

A role is a named list of things someone may do. People can hold more than one, and
holding two grants everything in both. Roles only ever add.

A new workspace comes with thirteen roles already defined. You can edit them, delete
them, or add your own, but they are a good starting vocabulary:

| Role | Give it to |
|---|---|
| **Administrator** | The one or two people who run the workspace. Full access, including users, roles and every setting. |
| **Billing Administrator** | Whoever owns the subscription and nothing else. |
| **Media Editor** | People who manage the library end to end: files, versions, albums. |
| **Media Uploader** | Photographers and anyone who adds files but should not reorganize the library. |
| **Media Viewer** | Read-only access to media and albums. |
| **Album Admin** | Creating and organizing albums and their contents. |
| **Knowledge Admin** | People who own what the AI knows. |
| **Knowledge Contributor** | People who write knowledge content without changing how it is configured. |
| **Knowledge Viewer** | Read-only access to knowledge bases. |
| **Designer** | People who build designs and publish templates. |
| **Design Contributor** | People who fill approved templates without changing their layout. |
| **Chat User** | Everyone who uses AI Chat. |
| **Power User** | Chat User, plus building agents and tools. |

The **Viewer / Contributor / Admin** pattern repeats across media, knowledge and design
by design. Once you know what a Contributor is in one area, you know it in all three.

## A starting set of roles

For most organizations, three tiers cover almost everyone:

1. **Everybody** gets **Chat User** and **Media Viewer**. They can ask the AI things
   and find files.
2. **The people who make things** add **Media Editor** and **Design Contributor**.
3. **One or two owners** get **Administrator**.

Add the narrower roles as they come up: **Media Uploader** for an outside photographer,
**Billing Administrator** for finance, **Designer** for whoever owns the templates.

Start narrower than feels comfortable. Widening a role takes seconds, while discovering
six months later that everyone could delete the library does not.

## What roles do not control

Roles control which **screens and actions** someone has. They do not control which
**items** someone sees inside a screen. That is the access list on the item itself, the
"Who can use this" control. A **Designer** can open the design editor; whether they can
open *your* design depends on who you shared it with.

See [permissions and access](/guide/admin/permissions) for how the two interact, and
[sharing and access](/guide/admin/sharing-and-access) for the item side.

## Remove someone

Open **Administration → Users**, select the person, and deactivate them. Deactivating
ends their access immediately while keeping their history, so what they uploaded and
changed stays attributed to them.

There is no delete, and that is deliberate: removal is always deactivation, so nothing
in the workspace ever loses its author. Reactivating someone later restores the same
account, against your plan's seat limit.

<Callout type="note">
	Every change to users and roles is recorded, with the before and after, in
	**Administration → History**. That is where to look when you need to answer "who
	granted this access?"
</Callout>
