Inviting with Access

When you invite someone to your organization, you also decide which environments they can see and whether they can change anything. That choice is part of the invite form, and it is applied the moment they accept.

This matters because a role on its own does not give anyone access to your variables. A Member or Viewer with no environment access sees an empty dashboard: no projects, no variables, nothing to do. Deciding it at invite time means your new teammate can start working the minute they accept.

Prerequisites

  • You are an Owner or an Admin of the organization. Members and Viewers cannot invite people.
  • Your plan has room for another team member. If not, you will see an upgrade prompt when you send the invitation.
  • The organization has at least one project with environments. If it does not, invite them anyway and grant access once you have created one.

Sending an invitation

Open the Team page

Go to Team in the sidebar. The invite form is at the top of the page.

Fill in the email address

Type the address of the person you want to invite. They will receive the invitation there, and they must sign up with that same address.

Pick a role

  • Admin can manage projects, environments, variables and team members. Only an Owner can invite an Admin.
  • Member works with variables in the environments you give them.
  • Viewer can look but never change anything.

For the full list, see Roles & Permissions.

Check the environment access

Underneath the role you will see every environment in your organization, grouped by project. EnvManager preselects a sensible default for the role you picked:

RolePreselected environmentsPreselected level
AdminAllRead & Write
MemberAllRead-only
ViewerAllRead-only (always)

Nothing is hidden and nothing is locked in. Untick any environment they should not see, and switch an environment to Read & Write if they need to make changes there. If you change the role, the selection resets to that role's default.

Viewers are always read-only. If you pick Viewer, the level control is fixed at Read-only, because that is what the server enforces anyway.

Send it

Click Send Invitation. The invitation appears in the Pending Invitations table and expires after 24 hours.

Untick everything if you want to hand out access later. The invitation still works, and the person will be told on their dashboard that an Owner or Admin still has to give them access.

What your teammate sees

The invitation email names the access you granted, for example "You'll have read access to 3 environments in Acme", so they know what to expect before they click.

After they accept:

  • If they have access to at least one environment, the confirmation screen offers Open your first project and takes them straight there.
  • If you gave them read-only access everywhere, their dashboard shows a short notice explaining that they have read-only access and that an Owner or Admin can give them write access in Team, under Access. They can dismiss it.
  • If they have no environment access at all, the dashboard tells them so honestly, and lists the Owners and Admins they can email to ask.

Changing access later

Access granted at invite time is not permanent, and it is not the only way to grant it.

Go to Team

Open Team in the sidebar and find the person in the Members table.

Open Access

Click Access on their row. The same environment list opens, with their current access ticked.

Adjust and save

Tick or untick environments, switch levels between Read-only and Read & Write, and click Save Changes. The change takes effect immediately.

Removing an environment here removes their access to its variables straight away, including anything they had already opened.

Frequently asked questions

Do Owners and Admins need environment access? They can see every project in the organization regardless. They do still need environment access to read variable values, which is why an Admin invitation preselects Read & Write everywhere.

What if I delete an environment before they accept? The invitation still works. The deleted environment is simply skipped and they get access to the rest.

Can I give someone write access to production only? Yes. Untick everything else, or set the other environments to Read-only and production to Read & Write. For protected environments their changes still go through the approval flow, see Protected Environments.

They accepted but still see nothing. Check the Members table on the Team page: if their row shows no environments, open Access and grant some.

Get DevOps tips in your inbox

Security best practices and product updates. No spam.

No spam. Unsubscribe anytime.