> ## Documentation Index
> Fetch the complete documentation index at: https://docs.livry.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Inviting and Managing Team Members

> Invite people to your Livry Team, grant them Environment access, change roles, and understand what happens when someone leaves.

Members are managed on the Team's **Members** page, by a Team **Admin** or **Owner**.

## Inviting someone

An invitation carries two things: a **Team role**, and **at least one Environment grant**.

<Warning>
  **Every invitation must name at least one Environment and a role in it** — with one exception.

  A **Billing** invitation carries no grant at all, because that role exists precisely to withhold
  access to your customers' brands.

  This is not a form-validation quirk. A Team role grants nothing inside an Environment, so an
  invitation with no grant would produce a member who could sign in and see nothing. See
  [Roles](/teams/roles).
</Warning>

The invitee gets an email. Sign-in is [passwordless](/settings/account), so accepting is following a
link and entering a code — there is no password for them to choose.

## When the grant takes effect

On their **first request after accepting**, not at the moment you invite them. Livry records the
pending invitation and turns it into a real membership the first time they actually arrive.

If somebody accepts an invitation and reports seeing nothing, have them reload once.

## Changing a role or a grant

Edit the member on the Members page. You can change their Team role and add or remove Environment
grants in the same edit.

<Note>
  **A change takes effect on the member's next request**, not their next sign-in. Nobody needs to log
  out and back in, and a removed grant stops working within about a minute.
</Note>

## Removing someone

Removing a member revokes their Team role and every Environment grant at once. Their account still
exists — accounts and Teams are separate, and one account can belong to several Teams.

## Leaving a Team yourself

From your own account area. Two guards:

* **The last Owner cannot leave.** Promote somebody else first; Livry refuses otherwise.
* If you are an Owner and there are others, you can leave and they carry on.

## Roles at a glance

| Give them | If they |
| - | - |
| **Member** + Editor on sandbox | Build and publish themes, and should not see production |
| **Member** + Editor on production | Publish to production, but not administer it |
| **Member** + Admin on production | Rotate signing keys, change allowlists, change integrations |
| **Member** + Viewer | Need to read and check, and change nothing |
| **Billing** | Handle invoices and nothing else |
| **Admin** | Manage people and Environments — **remember to grant them Environments too** |
| **Owner** | Should be able to initiate deletion of the Team |

<Note>
  The most common mistake is making somebody a Team Admin and assuming they can now see the themes.
  They cannot. Grant them the Environments as well.
</Note>

## Machine access

There is a place in the model for a **machine credential** — an identity with its own Team role and
Environment grants, for unattended automation.

<Warning>
  **It is not issuable yet.** Nothing provisions one, and the sign-in path does not resolve one, so
  the [Public API](/api/authentication) is reachable today only with a user-backed token.

  That means an API integration currently runs as a person. Plan for that, and see
  [What is not built yet](/help/limitations).
</Warning>

## Ceiling

Each Team is an organization in Livry's identity provider, and the current plan caps how many exist
across all of Livry. If you are planning to run many separate Teams rather than many Environments
under one, [talk to us first](/help/faq).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.