Skip to content
CredenShare
Teams

Members, Roles and Seats

Inviting people, what each role can actually do, how seats are counted and billed, and why a member of a paying team can still be told to upgrade.

Everything an owner or an admin needs to run a team's roster.

Two screens manage people. Members is account-wide: everyone across every team you own, with the seat count. My Teams → a team manages one team's list and is where roles are changed. The Members tab only appears on a plan that includes teams — Basic and above. Free and Solo have no team support; someone on Free or Solo who has been invited into another person's team keeps My Teams but never sees Members.

Inviting someone

From Members, click Invite Member:

  1. Enter one email address.
  2. Tick the teams to add them to. Every team you own is ticked by default.
  3. Click Continue. The app previews the seat cost.
  4. On the Confirm Invitation step, click Confirm & Send.

Leaving every team unchecked invites the person to your account only: they take a seat but reach no team data until you use Assign teams on their row. Whichever way you invite them, one person is one account seat regardless of how many of your teams they are in.

If the address is already in every team you selected, nothing is sent and the app says "No invites sent".

What the invitee sees

An invitation email arrives with a confirmation link. Opening it requires them to be signed in, then the page confirms the membership and shows Welcome to the team!. A bad or stale token gives Invitation Failed.

Someone who has never used CredenShare gets a different email, carrying the same confirmation link plus a second one — a CredenShare share holding their email address and a temporary password, titled "Your login information". That share destroys itself five minutes after it is first opened, so they should be ready to sign in when they click it.

The confirmation link is valid for 24 hours. After that the invitee must be sent a new one with Resend.

Delivery can take up to a minute. Resend is on a 60-second cooldown per invitee, deliberately, because resending early is what produces two emails instead of one.

Nothing takes effect until the invite is accepted. A pending member holds no team permissions, gets none of the team's plan features, and occupies no paid seat — the confirmation step says so: "You will only be charged for members who accept your invitation."

Members aggregates only the teams you own. An admin who owns no team of their own invites from the team's own page instead, which carries the same Invite Member button and the same Confirm & Send step.

Roles

Three roles exist: Owner, Admin and Member. There is exactly one owner per team — whoever created it.

OwnerAdminMember
Create shares in the team, and secure requests (Business and Enterprise)YesYesYes
See and manage their own shares and requestsYesYesYes
See every member's shares and secure requests in the teamYesYesNo
See the team's statisticsYesYesNo
Invite, resend and remove membersYesYesNo
Change another member's roleYesNoNo
Edit the team name and domain, and the team's branding (Business and Enterprise)YesYesNo
Create and edit the team's field templates (Business and Enterprise)YesYesNo
Use the team's field templates (Business and Enterprise)YesYesYes
Set the team-wide inactivity capYesNoNo
Grant and revoke the team key (Business and Enterprise)YesYesNo
Read the team's plan and entitlementsYesYesYes
Billing, seats and the subscriptionYesNoNo
Delete the teamYesNoNo
Read another member's access trailNoNoNo

A member who attempts an admin action is refused with "You do not have permission to perform this action on this team". Despite the wording, that message means your role is not high enough; it is not a sign that the team is broken.

Changing a role

Role changes happen on the team's own page, and only the owner sees the control. The app states what the change means before applying it:

  • Promoting to Admin — "Admins can invite + remove members, edit team settings, and see + manage every team share and secure request. Admins cannot manage billing — that stays with the Owner."
  • Demoting to Member — "Members can only see + manage their own shares and requests. They can no longer invite members, edit team settings, or view other members' team data."

The control is hidden on your own row, on the owner's row, and on anyone whose invitation is still pending: a member must accept before their role can be changed.

Ownership itself cannot be moved. There is no transfer-ownership flow and no way to appoint a second owner, so a team belongs permanently to the account that created it. If a different person should hold billing and ownership, create the team from their account.

Seats

A seat is a person, not a login session and not a team membership.

PlanIncluded seatsEach additional seat
FreeNone — no team support
SoloNone — no team support
Basic1$1 / month, or $10 / year
Plus5$2 / month, or $19 / year
Business5$4 / month, or $38 / year
EnterpriseUnlimited

Four rules decide the number:

  • The owner occupies the first seat. Basic's single included seat is the owner's own, so on Basic the first person you invite is already a paid seat. Plus and Business cover the owner plus four colleagues.
  • One person is one seat, however many of your teams they belong to.
  • Only confirmed members occupy a paid seat. Pending invitations are listed separately and cost nothing until they are accepted.
  • Seats are counted across every team you own, not per team.

When the included seats run out

Nothing is blocked. The next confirmed member simply becomes a billed seat, added automatically at the plan's rate, and the first charge is prorated to the days left in the current billing period. The invite step tells you which case you are in before you commit: either No extra charge, with "Covered by your plan's included seats." beneath it, or Prorated charge with the amount, and "Adds 1 paid seat" at the plan's rate beneath that.

The full picture lives on Profile & Account → Subscription, in the Team Seats card, which reports Included with plan, Currently occupied, Pending invitations, Free seats remaining, Paid seats (billed), Pre-purchased seats and Additional seat price.

Buy seats pre-purchases capacity. Pre-purchased seats act as a floor: they keep being billed after a member leaves, holding the seat for the next person rather than releasing it. Release appears only when you hold pre-purchased seats that current members are not using, and it gives those back.

A seat member has no plan of their own

This is the rule that catches nearly everyone.

Symptom. A colleague on your paid team is told they need to upgrade, sees Free-plan limits, or finds a feature the team pays for locked.

Cause. A seat member has no subscription of their own — they occupy one of yours. Judged personally they resolve to the Free plan, because that is what an account with no subscription is. Their entitlements come from the organisation, and the app resolves the team's plan only when a team context is selected.

Fix. Ask them to use the context switcher in the sidebar — it reads Personal by default and shows the team name once a team is selected — and to pick your team. Feature gating, plan limits and the share allowance then follow the team's plan instead of their own.

The same rule decides which allowance a share consumes. A share created in team context is attributed to the team and draws on the team's pool; a share the same person creates in Personal context is a personal share, judged against their own plan. See Plans and share allowance.

Entitlement through the organisation requires a confirmed membership. Someone who has been invited but has not clicked the confirmation link is still on their own plan, whatever the members list shows.

On Business and Enterprise, zero-knowledge custody reaches members the same way: the seat is what entitles a member to enrol and to receive the team key, even though they hold no plan of their own.

Removing a member

On Members, use the row action, tick the teams to remove them from, and confirm. Removing them from every team frees the seat — the app warns that "Removing from every team will free their account seat. They lose access to all shared data."

What removal does not do:

  • It does not touch their shares. Shares they created stay live and keep working for recipients until they expire. Removing the person does not delete, expire or reassign them.
  • It does not refund the share allowance. Shares already created stay counted for the rest of the period.
  • It does not revoke the team key. On a team using zero-knowledge, revoke the member's grant explicitly from the team page's Zero-knowledge for this team section; removing their membership leaves the grant in place.

Members cannot remove themselves. There is no "leave team" action, so a member who wants out must ask an owner or an admin. Members does not list your own row at all, the team's own page hides the remove action on it, and the owner's row can never be removed.

What no role can read

The access trail of a share belongs to the account that created it, and to nobody else. An owner or an admin can see that a member's share exists in the team's lists, but the trail behind it — timestamps, IP addresses, platform, failed password attempts — is refused to every other account, with the same message an under-privileged member gets: "You do not have permission to perform this action on this team".

The account-level audit export is scoped the same way: it returns your own history only. Owning the team, and paying for the seat, does not open another person's trail. See Key concepts for what the trail records and how long each plan keeps it.