Members and roles
LiveWho can do what in a workspace, how invites and seats work, and the rule that keeps every workspace with an owner.
The four roles
Everyone in a workspace has one of four roles. Here they are from most to least powerful. Each role can do everything the roles below it can.
| Role | What the app says | In practice |
|---|---|---|
| Owner | Everything, including billing | Full control. Only Owners can make someone an Owner, or change or remove an Owner. |
| Admin | Members, projects and settings | Invites people, changes roles, manages projects, connects apps, deletes agents and renames the workspace. |
| Builder | Builds and runs agents | Builds, tests, publishes and pauses agents, adds app actions to them, and approves or rejects their actions. |
| Viewer | Read-only | Sees the workspace, its agents, tasks and leads, without changing them. |
You can find this list in the app too: open Settings, then Members, and look under Roles.
Permissions
| Action | Owner | Admin | Builder | Viewer |
|---|---|---|---|---|
| See the workspace, its projects and its members | Yes | Yes | Yes | Yes |
| Switch project | Yes | Yes | Yes | Yes |
| Leave the workspace | Yes, unless you are the last Owner | Yes | Yes | Yes |
| See pending invites | Yes | Yes | No | No |
| Rename the workspace | Yes | Yes | No | No |
| Create and rename projects | Yes | Yes | No | No |
| Invite someone as Admin, Builder or Viewer | Yes | Yes | No | No |
| Invite someone as Owner | Yes | No | No | No |
| Revoke a pending invite | Yes | Yes | No | No |
| Change an Admin's, Builder's or Viewer's role | Yes | Yes, to Admin, Builder or Viewer | No | No |
| Make someone an Owner | Yes | No | No | No |
| Change an Owner's role | Yes | No | No | No |
| Remove an Admin, Builder or Viewer | Yes | Yes | No | No |
| Remove an Owner | Yes | No | No | No |
| See agents, tasks and leads | Yes | Yes | Yes | Yes |
| See connected apps | Yes | Yes | Yes | Yes |
| Create, edit, test, publish, pause and resume agents | Yes | Yes | Yes | No |
| Add app actions to an agent (pilot) | Yes | Yes | Yes | No |
| Add, change and delete an agent's schedules and webhooks | Yes | Yes | Yes | No |
| Approve or reject an agent's actions | Yes | Yes | Yes | No |
| Delete an agent | Yes | Yes | No | No |
| Connect, reconnect and disconnect apps (pilot) | Yes | Yes | No | No |
| See, create and revoke API keys | Yes | Yes | No | No |
| Buy credits, and change low-balance alerts and billing details | Yes | Yes | No | No |
| Delete the workspace (planned) | Yes | No | No | No |
If you try something your role doesn't allow, you'll see a message such as "This needs the Admin role or higher."
Invites
Owners and Admins invite people from Settings, then Members, then Invite. See Invite a teammate for the steps.
How invites work:
- Admins can invite Admins, Builders and Viewers. Only Owners can invite someone as an Owner. A new invite starts with the Builder role.
- The invite comes by email. The subject reads "(name) invited you to (workspace) on Dhanur AI", and the email links to the sign-in page with the address filled in.
- There is no accept button. The invite is accepted the next time that person signs in with the invited address, by email code or with Google. They go straight into the workspace and skip workspace setup.
- Already signed in? Invites are checked when you sign in. If the person was already signed in when you invited them, they should sign out and sign in again.
- The address must match. If they sign in with Google, the Google account must use the invited address.
- Pending invites are listed under Members as "Invited, waiting for sign-in". Only Owners and Admins can see them.
- Inviting the same address again updates the pending invite's role and sends the email again. It doesn't use another seat.
- Invites don't expire. To cancel one, select Revoke. After that, signing in with that address doesn't add the person.
- If the email doesn't arrive, the invite still stands. The person can go to app.dhanurai.com/login and sign in with the invited address.
- Existing members can't be invited again. You'll see "That person is already a member."
Seats
A seat is taken by each member and each pending invite. During early access, a workspace has 2 seats.
The top of Members shows how many seats are used, for example "2 of 2 seats used on your plan." Builders and Viewers can't see pending invites, so the count they see leaves those out.
When every seat is taken, a new invite fails with:
"Your plan includes 2 seats. Remove a member or revoke an invite first."
Changing roles
Owners and Admins change a role from the Role menu on a member's row. The change applies as soon as you pick it. There is no Save button. See Change a role.
- Admins can move people between Admin, Builder and Viewer.
- Admins can't change an Owner's role or make anyone an Owner. On an Owner's row, an Admin sees the role as a label rather than a menu.
- Owners can change anyone's role, including making someone an Owner.
- Admins can change their own role too. If you step down to Builder or Viewer, you can't change it back yourself.
Removing people and leaving
- Remove someone: Owners and Admins open the ⋯ menu on a member's row, choose Remove from workspace and confirm. Admins can't remove Owners. See Remove a member.
- Leave: anyone can open the ⋯ menu on their own row, marked "(you)", and choose Leave workspace. See Leave a workspace.
Either way, the person loses access to the workspace at once. Their Dhanur AI account and their other workspaces are not affected. To bring someone back, invite them again.
Every workspace keeps an owner
A workspace always has at least one Owner. The last Owner can't leave, be removed or be given another role. Trying to do so shows "A workspace needs at least one owner."
To hand a workspace over:
- Make the new person an Owner.
- Then change your own role, or leave.
It's a good idea to have two Owners, so the workspace is never locked out if one person leaves.
Audit trail
We record security-related actions in an audit log. These include creating or renaming a workspace or project, sending or revoking invites, people joining, role changes, removals, signing in and out, creating, publishing and deleting agents, approval decisions, and connecting or disconnecting apps.
Planned. A way to view and export the audit log. Until then, email us if you need a record.
Last updated 24 September 2026
Something unclear or wrong? Tell us