> For a complete page index, fetch https://docs.synthflow.ai/llms.txt. For full documentation content, fetch https://docs.synthflow.ai/llms-full.txt.

# Team members

> Learn about workspace roles and how to invite and manage team members in Synthflow.

Super Admins and Admins can invite new members from **Admin** → **Workspace Settings** → **Members**, assign roles on acceptance, and manage existing team access. Workspace access is controlled by [roles](#roles). You can also combine invitations with [allowed email domains](/security#allowed-email-domains), [Single Sign-On (SSO)](/security#single-sign-on), and [two-factor authentication (2FA)](/security#two-factor-authentication) to tighten who can join and how they sign in.

## Invitations

![User invitation modal](https://storage.googleapis.com/granular-changelog/doc-images/user-management-modal_2.png)

Users with the pertinent roles can invite users. Open **Admin** → **Workspace Settings** → **Members** and click **Invite User**.

Enter the invitee's email address and select the role they receive when they accept. You can generate a link to copy and share, or send the invitation directly to that email address. New users are added to your workspace when they accept the invitation. If the invitee already has a Synthflow account, they are added without receiving an email notification and can switch to the workspace from the workspace switcher.

Selecting a role assigns it automatically when the invite is accepted. The invitation is valid only for the specified email address.

## Roles

Synthflow has three workspace roles. The table below summarizes what each role can do.

| Capability                                                          | Super Admin | Admin                  | Member |
| ------------------------------------------------------------------- | ----------- | ---------------------- | ------ |
| Use core workspace features                                         | Yes         | Yes                    | Yes    |
| Invite and manage users                                             | Yes         | Yes                    | No     |
| Assign roles                                                        | Any role    | Any except Super Admin | No     |
| Remove or demote Super Admins                                       | Yes         | No                     | No     |
| Billing and subscriptions                                           | Yes         | Yes                    | No     |
| [Delete the workspace](/manage-billing#delete-your-workspace)       | Yes         | Yes                    | No     |
| API keys                                                            | Yes         | Yes                    | No     |
| [Allowed email domains](/security#allowed-email-domains)            | Yes         | Yes                    | No     |
| [SSO](/security#single-sign-on) configuration                       | Yes         | Yes                    | No     |
| Require [2FA](/security#two-factor-authentication) for team members | Yes         | Yes                    | No     |
| Primary workspace contact                                           | Yes         | No                     | No     |

### Super Admin

The Super Admin has full access to every feature and setting in the organization and serves as the primary contact for the workspace.

### Admin

Admins share the same management permissions as Super Admins except they cannot assign the Super Admin role or remove or demote existing Super Admins.

### Member

Members have standard access to core workspace features. They cannot invite users, change roles, or manage billing, API keys, or security settings.

## FAQ

Only Super Admins and Admins can invite users and assign roles. Members cannot invite or manage other users. See the [permission table](#roles) for the full breakdown.

Both roles can manage users, billing, API keys, allowed email domains, SSO, and mandatory 2FA. The key difference is that Admins cannot demote or remove Super Admins, and they cannot assign the Super Admin role.

No. Members have standard access to core features but cannot invite users, change roles, or manage workspace security settings.