# Team, privacy & access

Use **Settings → Team** for the accounts that can open your Blank workspace. Use **People** for activity from monitored devices. Employees do not need a dashboard invitation to report through the managed extension.

## Invite a member

Owners and admins can invite members. Only owners can invite or manage another owner.

1. Open [**Settings → Team**](/admin/#team) and choose **Invite member**.
2. Enter the recipient's **Work email**, choose a **Role**, and select **Send invitation**.
3. Check the **Invitations** list for the role, expiration, and email status.
4. The recipient opens the email, signs in with that same verified email, and explicitly accepts the invitation. One account belongs to one workspace; an account already in another workspace cannot join this one.

Invitations expire after 7 days. **Resend** renews the invitation and becomes available after the one-minute cooldown. **Revoke**, followed by **Confirm revoke**, prevents acceptance. **Email sent** means the message was accepted for sending; it does not confirm inbox delivery. If sending failed or is unconfirmed, refresh the team before resending.

## Change or remove access

Search the members list, choose **Manage** on the member, choose a new role, and select **Confirm role change**. To remove a member, choose **Remove access…** and confirm removal. Changes to your own role or membership change your access immediately.

The workspace must keep at least one owner. An owner must promote another member before downgrading or removing the final owner. Admins cannot manage owners. Directory-managed accounts must be updated through your identity provider.

Removing access also prevents SAML domain auto-join until the person accepts a new invitation or is actively provisioned by the directory. SCIM deprovisioning remains authoritative. If a write times out or its outcome is uncertain, use **Refresh team** before trying again.

## Roles

| Role | Access |
|---|---|
| Owner | Read, export, change policy/settings, manage members and owners, and manage billing. |
| Admin | Read, export, change policy/settings, and manage members other than owners. |
| Auditor | Read, export evidence, and inspect the audit log; cannot change policy/settings. |
| Viewer | Read workspace screens; cannot export or change policy/settings. |

All roles can manage their own [saved investigation views](/docs/dashboard/#saved-views). Permissions are enforced on the server. A bookmarked destination does not grant additional access.

## Privacy settings

Open [**Settings → Privacy & access → Privacy**](/admin/#settings?section=privacy). Owners and admins can edit these settings; other roles can read them.

- **Pseudonymise identities** replaces device and user identifiers with stable Person labels across views, exports, and API responses. It is on by default.
- **Capture matched content** controls whether already recorded matched content may appear in views and exports. It is off by default. The switch does not change browser collection: the extension does not transmit matched text.

Select **Save privacy settings** and wait for the saved confirmation. An enabled content setting does not create content for an existing record that contains none. See [Privacy and data handling](/data-handling/) for the collection scope and retention.

## Request a temporary identity reveal

With pseudonymization enabled, an owner or admin can request access to a device identifier for one Person record.

1. Open the record in **People**, choose **Request identity**, and provide a reason.
2. A different owner or admin opens [**Settings → Privacy & access → Identity access**](/admin/#settings?section=identity), reviews the reason, and chooses **Approve** followed by **Yes, reveal**, or **Deny**. The requester cannot approve their own request.
3. The requester returns to People and refreshes activity if prompted. Approval reveals that record's device identifier to the requester for 24 hours.

The reveal does not establish an employee name or grant access to captured content. Identifiers are hidden when the grant expires. Bulk device CSV and SIEM exports retain the workspace's pseudonymization setting rather than inheriting an administrator's temporary reveal. If the request is unconfirmed, choose **Check request status** before requesting again.

## Single sign-on and provisioning

Owners and admins use **Settings → Privacy & access → Single sign-on** for SAML and **Provisioning** for SCIM. Each section has its own link. Follow [SSO and SCIM](/docs/sso/) for setup, token rotation, and deprovisioning.

Edited Privacy and Single sign-on forms stay in memory when switching between these sections. Leaving the page asks **Keep editing** or **Discard changes** when a draft would be lost. Reloading does not restore a draft.

## Review workspace changes

Owners, admins, and auditors can open [**Settings → Audit log**](/admin/#audit). Search recorded actions, filter by actor/action/date, and expand an entry for readable changes and links to current settings. **Load older entries** continues through the same history; **Refresh history** starts a fresh read. Audit timestamps use UTC.

History omits secrets, captured content, employee identifiers, and personal saved-view names and filters. The audit log is read-only and has no export action. See the [dashboard audit-log reference](/docs/dashboard/#audit-log) for filter details.
