# Members and roles

> Invite people to your org, choose their role, and remove members safely.

Source: https://nodus-platform-site.pages.dev/docs/guides/access/members-and-roles/
Build revision: 211ad9f836655b1c3a2668c4693e442471f28614

## Roles

|Role|Can|
|-|-|
|**Owner**|Everything, including granting or removing the Owner role|
|**Admin**|Everything except the Owner role: members, invites, projects, API keys, service accounts, billing|
|**Member**|Create and manage work: jobs, sandboxes, volumes, secrets, their own API keys|
|**Viewer**|Read everything, change nothing|

`nodus auth can-i create jobs` asks the server whether you hold a permission.

## Invite someone

Terminal window

```bash
nodus create invite --email ada@example.com --role Member
```

The invite link works for 72 hours and only once. The invitee signs in with that email address (it must be verified) and accepts it in the console, where pending invites also appear as a banner. You can invite up to your seat limit, 10 members by default; pending invites count as seats. An invite nobody accepts stays under **Team › Invites** after it expires, marked Expired and holding no seat, so you can resend it. Once your org has bought credits, an Owner or Admin can change the seat limit under **Team › Members › Change**, up to 1,000. When an invite is accepted, or someone is made an Admin or Owner, every Owner and Admin gets an email.

Terminal window

```bash
nodus get invites
nodus request resend invite/inv-01j9abc     # a fresh link, at most 3 times, 10 minutes apart
nodus delete invite inv-01j9abc
```

You can invite someone with a role up to your own: Admins invite Admins, Members and Viewers; only Owners invite Owners.

## Let your company join without invites

An Owner or Admin adds your company’s email domain under **Team › Company domains**, then adds the TXT record shown there at your DNS provider and selects **Verify**. After that, anyone who signs up with a verified email at that domain is offered your org during sign-up and joins it as a Member in one click. Seats still apply, public mailbox domains such as `gmail.com` are refused, and a domain belongs to one org at a time. Remove the domain to stop new joins; people who already joined stay members. Someone you remove from the org can only come back through an invite.

## Change a role

Terminal window

```bash
nodus get members
nodus edit member usr-01j9abc --role Admin
```

An org always keeps at least one Owner: demoting or removing the last Owner is refused with `409 Conflict`.

## Remove a member

Terminal window

```bash
nodus delete member usr-01j9abc
nodus delete member usr-<your-id>     # leave an org yourself
```

Removing a member revokes their API keys and third-party app access in that org at once. Keys bound to a [service account](https://nodus-platform-site.pages.dev/docs/guides/access/service-accounts/) keep working, so CI does not break when the person who set it up leaves.
