[{"data":1,"prerenderedAt":951},["ShallowReactive",2],{"navigation":3,"/teams/members-roles-and-seats":258,"/teams/members-roles-and-seats-surround":946},[4,22,63,85,115,131,219,245],{"title":5,"path":6,"stem":7,"children":8,"page":21},"Getting Started","/getting-started","1.getting-started",[9,13,17],{"title":10,"path":11,"stem":12},"Introduction","/getting-started/introduction","1.getting-started/1.introduction",{"title":14,"path":15,"stem":16},"Quick Start","/getting-started/quick-start","1.getting-started/2.quick-start",{"title":18,"path":19,"stem":20},"Key Concepts","/getting-started/key-concepts","1.getting-started/3.key-concepts",false,{"title":23,"path":24,"stem":25,"children":26,"page":21},"Guides","/guides","2.guides",[27,31,35,39,43,47,51,55,59],{"title":28,"path":29,"stem":30},"Quick Share Guide","/guides/quick-share","2.guides/1.quick-share",{"title":32,"path":33,"stem":34},"Slack Integration","/guides/slack-integration","2.guides/2.slack-integration",{"title":36,"path":37,"stem":38},"Enterprise Setup","/guides/enterprise-setup","2.guides/3.enterprise-setup",{"title":40,"path":41,"stem":42},"Creating a Share","/guides/creating-a-share","2.guides/4.creating-a-share",{"title":44,"path":45,"stem":46},"Zero-Knowledge Custody","/guides/zero-knowledge-custody","2.guides/5.zero-knowledge-custody",{"title":48,"path":49,"stem":50},"Secure Requests","/guides/secure-requests","2.guides/6.secure-requests",{"title":52,"path":53,"stem":54},"Receiving a Secure Request","/guides/receiving-a-secure-request","2.guides/7.receiving-a-secure-request",{"title":56,"path":57,"stem":58},"SecurePaste","/guides/securepaste","2.guides/8.securepaste",{"title":60,"path":61,"stem":62},"Notifications","/guides/notifications","2.guides/9.notifications",{"title":64,"icon":65,"path":66,"stem":67,"children":68,"page":21},"Account","i-lucide-user-cog","/account","3.account",[69,73,77,81],{"title":70,"path":71,"stem":72},"Signing In","/account/signing-in","3.account/1.signing-in",{"title":74,"path":75,"stem":76},"Plans and Share Allowance","/account/plans-and-share-allowance","3.account/2.plans-and-share-allowance",{"title":78,"path":79,"stem":80},"Billing and Subscription","/account/billing-and-subscription","3.account/3.billing-and-subscription",{"title":82,"path":83,"stem":84},"Plans and Limits","/account/plans-and-limits","3.account/4.plans-and-limits",{"title":86,"icon":87,"path":88,"stem":89,"children":90,"page":21},"Teams","i-lucide-users","/teams","4.teams",[91,95,99,103,107,111],{"title":92,"path":93,"stem":94},"Teams and Contexts","/teams/teams-and-contexts","4.teams/1.teams-and-contexts",{"title":96,"path":97,"stem":98},"Members, Roles and Seats","/teams/members-roles-and-seats","4.teams/2.members-roles-and-seats",{"title":100,"path":101,"stem":102},"Joining a Team","/teams/joining-a-team","4.teams/3.joining-a-team",{"title":104,"path":105,"stem":106},"Custom Branding","/teams/custom-branding","4.teams/4.custom-branding",{"title":108,"path":109,"stem":110},"Policy and Audit","/teams/policy-and-audit","4.teams/5.policy-and-audit",{"title":112,"path":113,"stem":114},"Zero-Knowledge for Teams","/teams/zero-knowledge-for-teams","4.teams/6.zero-knowledge-for-teams",{"title":116,"path":117,"stem":118,"children":119,"icon":130},"Help","/help","5.help/0.index",[120,122,126],{"title":121,"path":117,"stem":118},"Help and Support",{"title":123,"path":124,"stem":125},"Link Not Working","/help/link-not-working","5.help/1.link-not-working",{"title":127,"path":128,"stem":129},"Error Messages","/help/error-messages","5.help/2.error-messages","i-lucide-life-buoy",{"title":132,"path":133,"stem":134,"children":135},"API Reference","/api","6.api/0.index",[136,137,141,167,189,193,211,215],{"title":132,"path":133,"stem":134},{"title":138,"path":139,"stem":140},"Authentication","/api/authentication","6.api/1.authentication",{"title":142,"path":143,"stem":144,"children":145},"Shares","/api/shares","6.api/2.shares/0.index",[146,147,151,155,159,163],{"title":142,"path":143,"stem":144},{"title":148,"path":149,"stem":150},"Create a share","/api/shares/create","6.api/2.shares/1.create",{"title":152,"path":153,"stem":154},"List shares","/api/shares/list","6.api/2.shares/2.list",{"title":156,"path":157,"stem":158},"Retrieve a share","/api/shares/retrieve","6.api/2.shares/3.retrieve",{"title":160,"path":161,"stem":162},"Expire a share","/api/shares/delete","6.api/2.shares/4.delete",{"title":164,"path":165,"stem":166},"Client-side encryption","/api/shares/client-side-encryption","6.api/2.shares/5.client-side-encryption",{"title":168,"path":169,"stem":170,"children":171},"Secure requests","/api/requests","6.api/3.requests/0.index",[172,173,177,181,185],{"title":168,"path":169,"stem":170},{"title":174,"path":175,"stem":176},"Create a request","/api/requests/create","6.api/3.requests/1.create",{"title":178,"path":179,"stem":180},"List and retrieve requests","/api/requests/list","6.api/3.requests/2.list",{"title":182,"path":183,"stem":184},"Read submissions","/api/requests/submissions","6.api/3.requests/3.submissions",{"title":186,"path":187,"stem":188},"Expire or delete a request","/api/requests/delete","6.api/3.requests/4.delete",{"title":190,"path":191,"stem":192},"Stats","/api/stats","6.api/4.stats",{"title":194,"path":195,"stem":196,"children":197},"Webhooks","/api/webhooks","6.api/5.webhooks/0.index",[198,199,203,207],{"title":194,"path":195,"stem":196},{"title":200,"path":201,"stem":202},"Event reference","/api/webhooks/events","6.api/5.webhooks/1.events",{"title":204,"path":205,"stem":206},"Verifying signatures","/api/webhooks/verifying-signatures","6.api/5.webhooks/2.verifying-signatures",{"title":208,"path":209,"stem":210},"Delivery and retries","/api/webhooks/delivery-and-retries","6.api/5.webhooks/3.delivery-and-retries",{"title":212,"path":213,"stem":214},"MCP server","/api/mcp","6.api/6.mcp",{"title":216,"path":217,"stem":218},"Errors and Rate Limits","/api/errors-and-limits","6.api/7.errors-and-limits",{"title":220,"path":221,"stem":222,"children":223},"SDKs","/sdks","7.sdks/0.index",[224,225,229,233,237,241],{"title":220,"path":221,"stem":222},{"title":226,"path":227,"stem":228},"Node SDK","/sdks/node","7.sdks/1.node",{"title":230,"path":231,"stem":232},"Python SDK","/sdks/python","7.sdks/2.python",{"title":234,"path":235,"stem":236},"Go SDK","/sdks/go","7.sdks/3.go",{"title":238,"path":239,"stem":240},"Rust SDK","/sdks/rust","7.sdks/4.rust",{"title":242,"path":243,"stem":244},"Conformance vectors","/sdks/conformance-vectors","7.sdks/5.conformance-vectors",{"title":246,"path":247,"stem":248,"children":249,"page":21},"Security","/security","8.security",[250,254],{"title":251,"path":252,"stem":253},"Encryption","/security/encryption","8.security/1.encryption",{"title":255,"path":256,"stem":257},"Compliance","/security/compliance","8.security/2.compliance",{"id":259,"title":96,"api":260,"body":261,"description":940,"extension":941,"links":260,"meta":942,"navigation":943,"path":97,"seo":944,"stem":98,"__hash__":945},"docs/4.teams/2.members-roles-and-seats.md",null,{"type":262,"value":263,"toc":922},"minimark",[264,268,287,292,302,329,339,342,347,357,364,379,385,388,399,403,418,608,611,615,622,631,634,637,641,644,723,726,752,756,767,800,810,814,817,823,836,846,853,862,865,869,875,878,902,908,912,915],[265,266,267],"p",{},"Everything an owner or an admin needs to run a team's roster.",[265,269,270,271,275,276,279,280,283,284,286],{},"Two screens manage people. ",[272,273,274],"strong",{},"Members"," is account-wide: everyone across every team you own, with the seat count. ",[272,277,278],{},"My Teams → a team"," manages one team's list and is where roles are changed. The Members tab only appears on a plan that includes teams — Basic and above. Free and Solo have no team support; someone on Free or Solo who has been invited into another person's team keeps ",[272,281,282],{},"My Teams"," but never sees ",[272,285,274],{},".",[288,289,291],"h2",{"id":290},"inviting-someone","Inviting someone",[265,293,294,295,297,298,301],{},"From ",[272,296,274],{},", click ",[272,299,300],{},"Invite Member",":",[303,304,305,309,312,319],"ol",{},[306,307,308],"li",{},"Enter one email address.",[306,310,311],{},"Tick the teams to add them to. Every team you own is ticked by default.",[306,313,314,315,318],{},"Click ",[272,316,317],{},"Continue",". The app previews the seat cost.",[306,320,321,322,325,326,286],{},"On the ",[272,323,324],{},"Confirm Invitation"," step, click ",[272,327,328],{},"Confirm & Send",[265,330,331,332,335,336,286],{},"Leaving every team unchecked invites the person to your account only: they take a seat but reach no team data until you use ",[272,333,334],{},"Assign teams"," on their row. Whichever way you invite them, one person is ",[272,337,338],{},"one account seat regardless of how many of your teams they are in",[265,340,341],{},"If the address is already in every team you selected, nothing is sent and the app says \"No invites sent\".",[343,344,346],"h3",{"id":345},"what-the-invitee-sees","What the invitee sees",[265,348,349,350,353,354,286],{},"An invitation email arrives with a confirmation link. Opening it requires them to be signed in, then the page confirms the membership and shows ",[272,351,352],{},"Welcome to the team!",". A bad or stale token gives ",[272,355,356],{},"Invitation Failed",[265,358,359,360,363],{},"Someone who has never used CredenShare gets a different email, carrying the same confirmation link plus a second one — a CredenShare share holding their email address and a temporary password, titled \"Your login information\". That share ",[272,361,362],{},"destroys itself five minutes after it is first opened",", so they should be ready to sign in when they click it.",[365,366,369],"callout",{"color":367,"icon":368},"warning","i-lucide-alert-triangle",[265,370,371,372,375,376,286],{},"The confirmation link is valid for ",[272,373,374],{},"24 hours",". After that the invitee must be sent a new one with ",[272,377,378],{},"Resend",[265,380,381,382,384],{},"Delivery can take up to a minute. ",[272,383,378],{}," is on a 60-second cooldown per invitee, deliberately, because resending early is what produces two emails instead of one.",[265,386,387],{},"Nothing takes effect until the invite is accepted. A pending member holds no team permissions, gets none of the team's plan features, and occupies no paid seat — the confirmation step says so: \"You will only be charged for members who accept your invitation.\"",[265,389,390,392,393,395,396,398],{},[272,391,274],{}," aggregates only the teams you own. An admin who owns no team of their own invites from the team's own page instead, which carries the same ",[272,394,300],{}," button and the same ",[272,397,328],{}," step.",[288,400,402],{"id":401},"roles","Roles",[265,404,405,406,409,410,413,414,417],{},"Three roles exist: ",[272,407,408],{},"Owner",", ",[272,411,412],{},"Admin"," and ",[272,415,416],{},"Member",". There is exactly one owner per team — whoever created it.",[419,420,421,437],"table",{},[422,423,424],"thead",{},[425,426,427,430,433,435],"tr",{},[428,429],"th",{},[428,431,408],{"align":432},"center",[428,434,412],{"align":432},[428,436,416],{"align":432},[438,439,440,453,464,476,487,498,509,520,531,542,553,564,575,586,597],"tbody",{},[425,441,442,446,449,451],{},[443,444,445],"td",{},"Create shares in the team, and secure requests (Business and Enterprise)",[443,447,448],{"align":432},"Yes",[443,450,448],{"align":432},[443,452,448],{"align":432},[425,454,455,458,460,462],{},[443,456,457],{},"See and manage their own shares and requests",[443,459,448],{"align":432},[443,461,448],{"align":432},[443,463,448],{"align":432},[425,465,466,469,471,473],{},[443,467,468],{},"See every member's shares and secure requests in the team",[443,470,448],{"align":432},[443,472,448],{"align":432},[443,474,475],{"align":432},"No",[425,477,478,481,483,485],{},[443,479,480],{},"See the team's statistics",[443,482,448],{"align":432},[443,484,448],{"align":432},[443,486,475],{"align":432},[425,488,489,492,494,496],{},[443,490,491],{},"Invite, resend and remove members",[443,493,448],{"align":432},[443,495,448],{"align":432},[443,497,475],{"align":432},[425,499,500,503,505,507],{},[443,501,502],{},"Change another member's role",[443,504,448],{"align":432},[443,506,475],{"align":432},[443,508,475],{"align":432},[425,510,511,514,516,518],{},[443,512,513],{},"Edit the team name and domain, and the team's branding (Business and Enterprise)",[443,515,448],{"align":432},[443,517,448],{"align":432},[443,519,475],{"align":432},[425,521,522,525,527,529],{},[443,523,524],{},"Create and edit the team's field templates (Business and Enterprise)",[443,526,448],{"align":432},[443,528,448],{"align":432},[443,530,475],{"align":432},[425,532,533,536,538,540],{},[443,534,535],{},"Use the team's field templates (Business and Enterprise)",[443,537,448],{"align":432},[443,539,448],{"align":432},[443,541,448],{"align":432},[425,543,544,547,549,551],{},[443,545,546],{},"Set the team-wide inactivity cap",[443,548,448],{"align":432},[443,550,475],{"align":432},[443,552,475],{"align":432},[425,554,555,558,560,562],{},[443,556,557],{},"Grant and revoke the team key (Business and Enterprise)",[443,559,448],{"align":432},[443,561,448],{"align":432},[443,563,475],{"align":432},[425,565,566,569,571,573],{},[443,567,568],{},"Read the team's plan and entitlements",[443,570,448],{"align":432},[443,572,448],{"align":432},[443,574,448],{"align":432},[425,576,577,580,582,584],{},[443,578,579],{},"Billing, seats and the subscription",[443,581,448],{"align":432},[443,583,475],{"align":432},[443,585,475],{"align":432},[425,587,588,591,593,595],{},[443,589,590],{},"Delete the team",[443,592,448],{"align":432},[443,594,475],{"align":432},[443,596,475],{"align":432},[425,598,599,602,604,606],{},[443,600,601],{},"Read another member's access trail",[443,603,475],{"align":432},[443,605,475],{"align":432},[443,607,475],{"align":432},[265,609,610],{},"A member who attempts an admin action is refused with \"You do not have permission to perform this action on this team\". Despite the wording, that message means your role is not high enough; it is not a sign that the team is broken.",[343,612,614],{"id":613},"changing-a-role","Changing a role",[265,616,617,618,621],{},"Role changes happen on the team's own page, and only the ",[272,619,620],{},"owner"," sees the control. The app states what the change means before applying it:",[623,624,625,628],"ul",{},[306,626,627],{},"Promoting to Admin — \"Admins can invite + remove members, edit team settings, and see + manage every team share and secure request. Admins cannot manage billing — that stays with the Owner.\"",[306,629,630],{},"Demoting to Member — \"Members can only see + manage their own shares and requests. They can no longer invite members, edit team settings, or view other members' team data.\"",[265,632,633],{},"The control is hidden on your own row, on the owner's row, and on anyone whose invitation is still pending: a member must accept before their role can be changed.",[265,635,636],{},"Ownership itself cannot be moved. There is no transfer-ownership flow and no way to appoint a second owner, so a team belongs permanently to the account that created it. If a different person should hold billing and ownership, create the team from their account.",[288,638,640],{"id":639},"seats","Seats",[265,642,643],{},"A seat is a person, not a login session and not a team membership.",[419,645,646,659],{},[422,647,648],{},[425,649,650,653,656],{},[428,651,652],{},"Plan",[428,654,655],{},"Included seats",[428,657,658],{},"Each additional seat",[438,660,661,672,681,692,703,713],{},[425,662,663,666,669],{},[443,664,665],{},"Free",[443,667,668],{},"None — no team support",[443,670,671],{},"—",[425,673,674,677,679],{},[443,675,676],{},"Solo",[443,678,668],{},[443,680,671],{},[425,682,683,686,689],{},[443,684,685],{},"Basic",[443,687,688],{},"1",[443,690,691],{},"$1 / month, or $10 / year",[425,693,694,697,700],{},[443,695,696],{},"Plus",[443,698,699],{},"5",[443,701,702],{},"$2 / month, or $19 / year",[425,704,705,708,710],{},[443,706,707],{},"Business",[443,709,699],{},[443,711,712],{},"$4 / month, or $38 / year",[425,714,715,718,721],{},[443,716,717],{},"Enterprise",[443,719,720],{},"Unlimited",[443,722,671],{},[265,724,725],{},"Four rules decide the number:",[623,727,728,734,740,746],{},[306,729,730,733],{},[272,731,732],{},"The owner occupies the first seat."," Basic's single included seat is the owner's own, so on Basic the first person you invite is already a paid seat. Plus and Business cover the owner plus four colleagues.",[306,735,736,739],{},[272,737,738],{},"One person is one seat",", however many of your teams they belong to.",[306,741,742,745],{},[272,743,744],{},"Only confirmed members occupy a paid seat."," Pending invitations are listed separately and cost nothing until they are accepted.",[306,747,748,751],{},[272,749,750],{},"Seats are counted across every team you own",", not per team.",[343,753,755],{"id":754},"when-the-included-seats-run-out","When the included seats run out",[265,757,758,759,762,763,766],{},"Nothing is blocked. The next confirmed member simply becomes a billed seat, added automatically at the plan's rate, and the first charge is prorated to the days left in the current billing period. The invite step tells you which case you are in before you commit: either ",[272,760,761],{},"No extra charge",", with \"Covered by your plan's included seats.\" beneath it, or ",[272,764,765],{},"Prorated charge"," with the amount, and \"Adds 1 paid seat\" at the plan's rate beneath that.",[265,768,769,770,773,774,777,778,409,782,409,785,409,788,409,791,409,794,413,797,286],{},"The full picture lives on ",[272,771,772],{},"Profile & Account → Subscription",", in the ",[272,775,776],{},"Team Seats"," card, which reports ",[779,780,781],"em",{},"Included with plan",[779,783,784],{},"Currently occupied",[779,786,787],{},"Pending invitations",[779,789,790],{},"Free seats remaining",[779,792,793],{},"Paid seats (billed)",[779,795,796],{},"Pre-purchased seats",[779,798,799],{},"Additional seat price",[265,801,802,805,806,809],{},[272,803,804],{},"Buy seats"," pre-purchases capacity. Pre-purchased seats act as a floor: they keep being billed after a member leaves, holding the seat for the next person rather than releasing it. ",[272,807,808],{},"Release"," appears only when you hold pre-purchased seats that current members are not using, and it gives those back.",[288,811,813],{"id":812},"a-seat-member-has-no-plan-of-their-own","A seat member has no plan of their own",[265,815,816],{},"This is the rule that catches nearly everyone.",[265,818,819,822],{},[272,820,821],{},"Symptom."," A colleague on your paid team is told they need to upgrade, sees Free-plan limits, or finds a feature the team pays for locked.",[265,824,825,828,829,831,832,835],{},[272,826,827],{},"Cause."," A seat member has no subscription of their own — they occupy one of yours. Judged personally they resolve to the ",[272,830,665],{}," plan, because that is what an account with no subscription is. Their entitlements come from the ",[272,833,834],{},"organisation",", and the app resolves the team's plan only when a team context is selected.",[265,837,838,841,842,845],{},[272,839,840],{},"Fix."," Ask them to use the context switcher in the sidebar — it reads ",[272,843,844],{},"Personal"," by default and shows the team name once a team is selected — and to pick your team. Feature gating, plan limits and the share allowance then follow the team's plan instead of their own.",[265,847,848,849,286],{},"The same rule decides which allowance a share consumes. A share created in team context is attributed to the team and draws on the team's pool; a share the same person creates in Personal context is a personal share, judged against their own plan. See ",[850,851,852],"a",{"href":75},"Plans and share allowance",[365,854,855],{"color":367,"icon":368},[265,856,857,858,861],{},"Entitlement through the organisation requires a ",[272,859,860],{},"confirmed"," membership. Someone who has been invited but has not clicked the confirmation link is still on their own plan, whatever the members list shows.",[265,863,864],{},"On Business and Enterprise, zero-knowledge custody reaches members the same way: the seat is what entitles a member to enrol and to receive the team key, even though they hold no plan of their own.",[288,866,868],{"id":867},"removing-a-member","Removing a member",[265,870,871,872,874],{},"On ",[272,873,274],{},", use the row action, tick the teams to remove them from, and confirm. Removing them from every team frees the seat — the app warns that \"Removing from every team will free their account seat. They lose access to all shared data.\"",[265,876,877],{},"What removal does not do:",[623,879,880,886,892],{},[306,881,882,885],{},[272,883,884],{},"It does not touch their shares."," Shares they created stay live and keep working for recipients until they expire. Removing the person does not delete, expire or reassign them.",[306,887,888,891],{},[272,889,890],{},"It does not refund the share allowance."," Shares already created stay counted for the rest of the period.",[306,893,894,897,898,901],{},[272,895,896],{},"It does not revoke the team key."," On a team using zero-knowledge, revoke the member's grant explicitly from the team page's ",[272,899,900],{},"Zero-knowledge for this team"," section; removing their membership leaves the grant in place.",[265,903,904,905,907],{},"Members cannot remove themselves. There is no \"leave team\" action, so a member who wants out must ask an owner or an admin. ",[272,906,274],{}," does not list your own row at all, the team's own page hides the remove action on it, and the owner's row can never be removed.",[288,909,911],{"id":910},"what-no-role-can-read","What no role can read",[265,913,914],{},"The access trail of a share belongs to the account that created it, and to nobody else. An owner or an admin can see that a member's share exists in the team's lists, but the trail behind it — timestamps, IP addresses, platform, failed password attempts — is refused to every other account, with the same message an under-privileged member gets: \"You do not have permission to perform this action on this team\".",[265,916,917,918,921],{},"The account-level audit export is scoped the same way: it returns your own history only. Owning the team, and paying for the seat, does not open another person's trail. See ",[850,919,920],{"href":19},"Key concepts"," for what the trail records and how long each plan keeps it.",{"title":923,"searchDepth":924,"depth":925,"links":926},"",1,2,[927,931,934,937,938,939],{"id":290,"depth":925,"text":291,"children":928},[929],{"id":345,"depth":930,"text":346},3,{"id":401,"depth":925,"text":402,"children":932},[933],{"id":613,"depth":930,"text":614},{"id":639,"depth":925,"text":640,"children":935},[936],{"id":754,"depth":930,"text":755},{"id":812,"depth":925,"text":813},{"id":867,"depth":925,"text":868},{"id":910,"depth":925,"text":911},"Inviting people, what each role can actually do, how seats are counted and billed, and why a member of a paying team can still be told to upgrade.","md",{},true,{"title":96,"description":940},"QSA8hcvmU5vOJptYmWZhKKnnSGSCJnBGQASH78GXDlk",[947,949],{"title":92,"path":93,"stem":94,"description":948,"children":-1},"Every share belongs to exactly one context — your personal space or one team. How to switch, where a new share lands, and who can see it.",{"title":100,"path":101,"stem":102,"description":950,"children":-1},"What the invitation looks like, how to accept it before it expires, and what changes for your account once you are a member.",1788908849633]