# Team members and roles

> Invite people to work on your intoCHAT agents as Admin, Editor, Viewer or a custom role: seats per plan, invitations, what each role can do, access to selected agents, the audit log, switching accounts and the limits.

You can invite people to work in your intoCHAT account. Each person signs in with their own intoCHAT login and gets a role, **Admin**, **Editor** or **Viewer** (or, on Enterprise, a [custom role](#custom-roles)), that decides what they can do with your agents. You can also [limit someone to selected agents](#access-to-selected-agents). You manage the team under **Settings**, **Team** in the sidebar.

## How a team works

- The account stays yours. Your agents, plan, limits and billing don't move. Members work on your agents in your account. They don't get copies.
- Agents a member creates or duplicates belong to your account and count toward your plan's agents. The training characters, website crawls and messages they use count toward your plan too, including their chats in the **Playground**.
- A role applies to every agent the person can work on: all agents in your account, or only the agents you selected for them. See [Access to selected agents](#access-to-selected-agents).
- Each member keeps their own intoCHAT account, with its own agents and plan. Joining yours doesn't change it. They [switch between the accounts](#switch-between-accounts) from the menu under their name.
- A private agent answers members working in your account in the **Playground**, as it answers you. See [Allowed domains](/en/docs/allowed-domains#private-agents).
- A new role, a change to their agents or to their custom role, or a removal takes effect on the person's next click.
- When someone is removed or leaves, the agents and the changes they made stay in your account.

## Seats per plan

| | Free | Starter | Pro | Enterprise |
| --- | --- | --- | --- | --- |
| Team members | None | 2 | 5 | Unlimited |

- You, the owner, don't use a seat.
- Everyone on the **Members** list besides the owner uses a seat, whether they have accepted or are still invited. An expired invitation keeps its seat until you resend or revoke it.
- The **Invite people** card shows how many seats are used, for example "1 of 2 seats used".
- When every seat is used, the card says **All seats are used** instead of showing the form, with a **See plans** button. Revoke an invitation, remove someone or upgrade to invite more. On the Free plan the card says **Team members are included from Starter**.

### After a downgrade

A plan change never removes anyone. If your new plan has fewer seats than people on your team, everyone keeps their access and role, and invitations already sent can still be accepted. You can't send new invitations until fewer people are on the list than your plan has seats. Until then the card says **More members than your plan includes**.

## Invite someone

The owner and admins can invite people.

1. Go to **Settings**, **Team**.
2. Under **Invite people**, enter the person's **Email**.
3. Choose a **Role**: **Admin**, **Editor** or **Viewer**. **Editor** is selected by default. Only the owner can invite admins, so an admin sees only **Editor** and **Viewer**. On Enterprise, the owner can choose one of the account's [custom roles](#custom-roles) instead.
4. Choose the **Agents** they can work on: **All agents** (the default) or **Selected agents**, then pick the agents. See [Access to selected agents](#access-to-selected-agents).
5. Click **Send invitation**.

The person appears under **Members** with the status **Invited**. If the email couldn't be sent, the invitation is saved anyway: click **Resend** in the list to try again.

An invitation is refused when:

- the address is yours or the account owner's;
- the address is already on the list. For a pending invitation, use **Resend** instead;
- no seat is free;
- the account has already sent 20 invitations within the hour. Resends count too.

### The invitation email

The subject is "[inviter] invited you to [account]'s intoCHAT account". The inviter is the person who sent it, and the account is yours. Each is shown by the name in their profile, or by their email address when there is no name. The email says:

- who invited them, to whose account, and with which role;
- what the role can do, in the words of the [roles](#roles) table's descriptions. For a custom role it says "A role the account owner set up, with its own permissions.";
- an **Accept the invitation** button;
- "The invitation expires in 7 days. Sign in, or create an account, with this email address to accept it."

After 7 days the link stops working and the list shows **Invitation expired**. Click **Resend** to send a new link.

## Accept an invitation

1. Click **Accept the invitation** in the email.
2. If you aren't signed in, the page shows the role and the address the invitation was sent to, partly hidden. It doesn't say whose account it is yet. Click **Sign in**, or **Create account** if you don't have an intoCHAT account. Use the address the invitation was sent to. Creating an account is free, and you come back to the invitation afterwards.
3. Signed in with that address, you see whose account it is and what your role can do. Click **Accept invitation**.

The dashboard opens in the account you joined, and you can start working straight away. Your own account stays as it is.

- **Signed in with another address**: the page says "This invitation is for a different email address". Click **Sign out**, then sign in or create an account with the address the invitation was sent to.
- Only the invited address can accept, whatever its capitalization. Someone who gets a forwarded link can't use it.
- **"This invitation isn't valid"**: the link is mistyped, already used, or replaced by a newer email after a **Resend**.
- **"This invitation has expired"**: ask whoever invited you to send it again.

## Roles

| | Owner | Admin | Editor | Viewer |
| --- | --- | --- | --- | --- |
| See agents and their settings, conversations and transcripts, leads, form submissions, bookings, the dashboard and stats | Yes | Yes | Yes | Yes |
| Download CSV and ZIP exports | Yes | Yes | Yes | Yes |
| Chat with an agent in the **Playground** with its saved settings | Yes | Yes | Yes | Yes |
| See an agent's [settings history](/en/docs/settings-history) and compare versions | Yes | Yes | Yes | Yes |
| See the plan and what it has used | Yes | Yes | Yes | Yes |
| See the team under **Settings**, **Team** | Yes | Yes | Yes | Yes |
| Follow live chats in the **Live chat** inbox | Yes | Yes | Yes | Yes |
| Create and duplicate agents | Yes | Yes | Yes | No |
| Create, rename and delete [agent folders](/en/docs/quick-start#organize-agents-in-folders), and move agents between them | Yes | Yes | Yes | No |
| Change an agent: setup, appearance, knowledge (add, delete, train, resync, crawl settings), Q&A, actions, custom buttons, chat forms, lead settings, topics, web search, visitor attachments, allowed domains, limits and access, Help Page and preview links | Yes | Yes | Yes | No |
| Test unsaved instructions in the **Playground** | Yes | Yes | Yes | No |
| Improve an answer from a transcript, and answer or dismiss **Questions to improve** | Yes | Yes | Yes | No |
| Import pages from a connected Notion workspace | Yes | Yes | Yes | No |
| Delete conversations, leads and form submissions | Yes | Yes | Yes | No |
| Switch an existing webhook or booking on or off, change the events a webhook or Slack alerts send, change the booking event type, send tests, resend webhook deliveries | Yes | Yes | Yes | No |
| Switch [live chat](/en/docs/live-chat) and its ratings on or off, take over waiting chats, and reply to and end the live chats they took over | Yes | Yes | Yes | No |
| Delete an agent | Yes | Yes | No | No |
| [Transfer an agent](/en/docs/transfer-agent) to another account, or cancel its transfer link | Yes | Yes | No | No |
| Restore an earlier version of an agent's settings | Yes | Yes | No | No |
| Take over a chat in which the visitor didn't ask for a person, and reply to or end a colleague's live chat | Yes | Yes | No | No |
| Add or delete a webhook, change its URL, rotate its secret | Yes | Yes | No | No |
| Set, replace or remove the Slack webhook URL | Yes | Yes | No | No |
| Connect, replace or remove a Cal.com API key or Calendly token | Yes | Yes | No | No |
| Connect or disconnect Notion | Yes | Yes | No | No |
| Invite, change and remove editors and viewers | Yes | Yes | No | No |
| Invite, change and remove admins | Yes | No | No | No |
| Limit editors and viewers to selected agents | Yes | Yes | No | No |
| See the [audit log](/en/docs/audit-log) (Pro and Enterprise) | Yes | Yes | No | No |
| Create, change, delete and assign [custom roles](#custom-roles) (Enterprise) | Yes | No | No | No |
| Change the plan, see the price and payment card, open the billing portal | Yes | No | No | No |

The Team page and the invitation email describe the roles like this:

- **Admin**: "Everything except billing. Can manage editors and viewers."
- **Editor**: "Build and change agents, knowledge and settings. Can't delete agents, add or remove webhooks, or connect Slack, Cal.com, Calendly or Notion."
- **Viewer**: "Read-only."

In [live chat](/en/docs/live-chat#who-can-do-what), a viewer's open inbox doesn't count as someone online, because viewers can't reply. When the owner or an admin replies in a chat a colleague is answering, they take it over, and the visitor sees their name from then on. An editor can't take a chat from a colleague.

Controls a role can't use are hidden, for example **New agent** for a viewer. If a request is refused anyway, the message says "Your role in this account (Viewer) doesn't allow this. Ask the account owner or an admin.", with the person's role, or their custom role's name, in the brackets.

## Access to selected agents

By default a member works on **All agents**: every agent in your account, including agents created later. You can instead give them **Selected agents** and pick which ones, when you invite them or later from the **Members** list. The owner and admins can do this; only the owner can do it for someone with a custom role.

A member limited to selected agents:

- sees only those agents, everywhere: the agents list, the dashboard and its stats, conversations and transcripts, leads, exports and the **Live chat** inbox. Their totals on the dashboard count only their agents;
- gets "not found" for any other agent, as if it were in another account. A link to another agent doesn't reveal that it exists;
- keeps any agent they create or duplicate: it is added to their list automatically. It still belongs to your account and counts toward your plan;
- can't change account-wide settings: inviting, changing or removing people, creating or revoking API keys, connecting or disconnecting Notion (the Notion connection is shared by all agents), or installing the Shopify app. Even when their role would allow these, they're refused with "Your access is limited to selected agents, so you can't change account-wide settings. Ask the account owner or an admin.";
- can't see the [audit log](/en/docs/audit-log), which covers the whole account.

Within their agents, their role decides what they can do, as for any member. They still see the team list, the list of API keys (prefixes only) and the plan, if their role allows it.

Admins always work on all agents, and so does a custom role with **Manage** on **Team** or **API keys**: both reach every agent anyway, through people they invite or a key they create. To limit someone, give them **Editor**, **Viewer** or a custom role without those.

An agent that is deleted disappears from everyone's list. If you select no agents, the member sees no agents until you add some.

While a limited member works in your account, the banner at the top says which agents they work on, for example "You're working in [name]'s account as Editor, on Support and Sales."

## Custom roles

On the Enterprise plan, the owner can define roles of their own under **Settings**, **Team**, in the **Roles** section, and give them to people instead of **Admin**, **Editor** or **Viewer**. A role is a name and one level for each area of the account:

| Area | What it covers | Levels |
| --- | --- | --- |
| Agent settings | Agents and their settings, appearance, sharing, settings history and Playground tests. Manage: delete agents, restore versions, the identity secret. | None, View, Edit, Manage |
| Knowledge | Sources, training, resync, crawl settings, Notion pages. | None, View, Edit, Manage |
| Actions & procedures | Actions, forms and procedures. | None, View, Edit, Manage |
| Leads & contacts | Leads, form submissions, bookings and return requests, and the lead form. | None, View, Edit, Manage |
| Conversations & live chat | Conversations, transcripts, exports and the live chat inbox. | None, View, Edit, Manage |
| Analytics | Topics, content gaps and knowledge usage. | None, View, Edit, Manage |
| Integrations & webhooks | Webhooks, Slack, booking, store, helpdesk, Notion and Shopify connections. Manage: credentials and signing secrets. | None, View, Edit, Manage |
| Team | Who is on the team. Manage: invite and remove people (not admins), and the audit log. | None, View, Manage |
| Billing | The plan and usage. Changing the plan stays with the owner. | None, View |
| API keys | The list of API keys. Manage: create and revoke them. | None, View, Manage |

- **View** reads, **Edit** also changes, **Manage** also does what the roles table above gives only to admins in that area, such as deleting an agent or adding a webhook. **None** hides the area: requests to it are refused.
- Any area inside an agent (Knowledge, Actions & procedures, Leads & contacts, Conversations & live chat, Analytics, Integrations & webhooks) needs at least **View** on **Agent settings**, or the agents can't be opened. The **Roles** form refuses a role that breaks this.
- In the **Live chat** inbox, **Edit** on **Conversations & live chat** works like an editor (take over waiting chats, reply to and end your own), and **Manage** like an admin (also take over chats nobody asked a person for, and step in on a colleague's).
- **Billing** goes up to **View**. Changing the plan, the payment card and the billing portal stay with the owner.
- A custom role with **Manage** on **Team** can invite, change and remove editors and viewers, like an admin. Only the owner can invite or change admins, and assign custom roles.

The built-in roles are fixed sets of these levels: **Admin** has **Manage** everywhere except **Billing** (**View**); **Editor** has **Edit** on every agent area and **View** on **Team**, **Billing** and **API keys**; **Viewer** has **View** everywhere. Their permissions don't change.

Rules:

- Only the owner can create, rename, change, delete and assign custom roles, and change or remove someone who has one.
- An account can have up to 20 custom roles. A name can be up to 40 characters, must be unique in the account, and can't be Owner, Admin, Editor or Viewer.
- Changing a role's levels applies to everyone who has it, on their next click.
- A role someone has can't be deleted. Give them another role first.
- A role with **Manage** on **Team** or **API keys** can't be given to someone limited to selected agents.
- If your account leaves Enterprise, nothing changes for the people who have a custom role: their role keeps applying. You can't create, change or assign custom roles until you're back on Enterprise, but you can still move people to a built-in role and delete roles nobody has.

## Audit log

On Pro and Enterprise, the owner and admins can see who changed what in the account, from which network and when, under **Settings**, **Audit log**: agents created, changed or deleted, sources, actions, webhooks and integrations, API keys, team changes and exports. See [Audit log](/en/docs/audit-log).

## Switch between accounts

Once you belong to someone else's account, the menu under your name at the bottom of the sidebar has a **Switch account** section. It lists **My account** and each account you're a member of, with your role there. A check mark shows the account you're in. Choose another to reload the dashboard in it.

While you work in someone else's account, a banner at the top of the dashboard says "You're working in [name]'s account as [role]." Click **Switch to my account** to go back.

- The account you chose is remembered in that browser for up to 30 days. After that, or in another browser, you start in your own account.
- If you're removed while working in an account, the next page you open shows your own account.

## Manage members and invitations

Under **Members** on **Settings**, **Team**, the list shows each person with their **Role**, **Status** (**Active**, **Invited** or **Invitation expired**) and the date they were invited or joined. The owner is listed first. Owners and admins get these controls in the **Actions** column:

- **Change a role**: choose another role in the **Role** column. On Enterprise, the owner can also choose a custom role there. It applies on the person's next click.
- **Change agents**: switch between **All agents** and **Selected agents**, and change which agents. It applies on the person's next click.
- **Resend**, for invitations: sends a new link that is valid for 7 days. The link in the earlier email stops working. It doesn't take another seat.
- **Revoke**, for invitations: the link in the email stops working and the seat is free again. You can invite the person again later.
- **Remove**, for members who accepted: they lose access on their next click and the seat is free again. Their work on the agents stays. You can invite them again later.

**Resend**, **Revoke** and **Remove** ask you to confirm first.

### Who can manage whom

- The owner can change, resend, revoke and remove anyone on the list, admins included.
- An admin can do this for editors and viewers only. Only the owner can invite an admin, make someone an admin, or change, resend, revoke or remove an admin.
- Only the owner can assign a custom role, or change, resend, revoke or remove someone who has one. A custom role with **Manage** on **Team** can manage editors and viewers, like an admin.
- Nobody can change their own role. Your own row has no controls.
- Editors and viewers see the list without controls.

## What stays personal

Some things always belong to the person signed in, whichever account they work in:

- **Profile and password**, under **Settings**, **Account**. Deleting your user there deletes your own account and its agents, not an account you're a member of. The plan shown on that page is the one of the account you're working in.
- **The [partner program](/en/docs/partner-program)**. Your partner link, commissions and payout email are yours, whichever account you work in.
- **Receiving a transferred agent**. An agent you accept with a [transfer link](/en/docs/transfer-agent) goes into your own account, not one you're a member of.
- **Notification emails**. The switches under **Notifications** change only your own emails, which cover your own account's agents. Usage alerts, the daily summary and weekly insights for your account go to you, the owner, and never to members.
- **Billing**. A member who opens **Billing** in your account sees "Billing for this account is managed by its owner." with your plan and what it has used this period. They don't see the price or payment card, and they can't change the plan or open the billing portal. This applies to admins too. Their own billing is in their own account.

Lead alerts are set per agent. **Send to me** on the **Leads** tab is the account owner's address, shown next to it, also when a member saves the settings. To get lead alerts as a member, add your address under **Also send to**. See [Alerts and export](/en/docs/lead-alerts-and-export).

## Members who sign in with SSO

On Enterprise, the owner can set up [single sign-on](/en/docs/single-sign-on). Then:

- Someone with an address on one of the account's verified domains who signs in with SSO for the first time joins the team without an invitation, with the role the owner chose for new members, and takes a seat like anyone else. A pending invitation to that address is accepted instead, with its own role.
- They appear in the **Members** list like invited members. You can change their role or remove them here. If they can still sign in at your identity provider, their next SSO sign-in adds them again, so remove their access there too.
- If the owner requires SSO, members with an address on those domains can't sign in with a password or Google. The owner always can.

## Leave an account

1. Go to **Settings**, **Team**.
2. Under **Accounts you're a member of**, click **Leave** next to the account.
3. Confirm with **Leave**.

You lose access straight away and your seat is free again. If you were working in that account, the dashboard reloads in your own. To come back, someone there has to invite you again. The owner can't leave their own account.

## Limits

- Each account has one owner. Ownership of the account can't be transferred to someone else, and the owner can't be removed. Single agents can be moved to another account: see [Transfer an agent](/en/docs/transfer-agent).
- A member's role is the same on every agent they work on. You can limit which agents, not give different roles on different agents.
- Custom roles are Enterprise only, up to 20 per account, and only the owner manages them.
- The [audit log](/en/docs/audit-log) is shown on Pro and Enterprise, and keeps 90 or 365 days. It doesn't record what people read, only what they change, plus exports.
- Single sign-on and automatic membership are Enterprise only. On other plans, each member is invited and signs in with their own intoCHAT login. See [Single sign-on](/en/docs/single-sign-on).
- No way to require [two-factor authentication](/en/docs/two-factor) from members. The **Members** list shows a **2FA** badge next to active members who turned it on.
- An invitation can only be accepted with the address it was sent to, and you can't edit that address. To invite another address, revoke the invitation and send a new one.
- The invitation is the only team email. The owner isn't told by email when someone accepts or leaves, and members aren't told when their role changes or they're removed. On Pro and Enterprise, the [audit log](/en/docs/audit-log) shows these changes.
- Seats come with the plan. On a monthly Starter or Pro plan you can add [extra seats](/en/docs/plans-and-limits#extra-agents-and-seats) for $9 a month each; otherwise, for more seats, move to a bigger plan.
- If the owner deletes their intoCHAT account, the team is deleted with it.
