Users, roles and permissions
This page is about your team: the colleagues who work in the Cockpit. It is not about the people who buy from you.
Invite a colleague
- Go to Settings › Team, tab Members.
- Select Invite member.
- Fill in Given name, Family name, Email and Preferred language.
- Send it.
They receive an initialisation email, set their own password with the identity provider, and from then on sign in through single sign-on. You never see or set their password.
The member list shows a state for each person, Active, Invited, Suspended or Locked, and the filter chips above it narrow to each. An invitation that was never accepted sits at Invited; Resend invitation sends it again.
When somebody leaves
Two different actions, and the difference matters:
| Action | What it does | Use it when |
|---|---|---|
| Suspend | Blocks sign-in. The account stays. | Someone is on parental leave, between contracts, or under investigation |
| Remove from organisation | Deletes their identity-provider record. Permanent. | Someone has left for good |
Suspend is the safe default. Removal cannot be undone, and a removed person has to be invited again from scratch. Reactivate reverses a suspension.
Whichever you choose, do it the day the person leaves, not at the end of the month. Then check the Sessions tab: suspending an account does not end a session that is already open.
Roles today
Access to the Cockpit is a matter of membership. Somebody who is a member of your organisation in the identity provider can sign in; somebody who is not, cannot. Every colleague you invite gets the same Cockpit access.
Do not confuse this with CRM › Roles. That screen is real and works today, and it defines what your customers' buyers may do in your shop. It has nothing to do with Cockpit access.
Watch the sessions
Settings › Team › Sessions lists the active sign-ins for your whole organisation, not only your own devices. The columns are Device / Browser, Auth Factors (password, passkey, totp, sms otp, email otp, sso) and Activity & Expiration: when the session was last active and when it expires.
Terminate Session ends one. Do that for any session nobody can account for, and have the account it belongs to change its password afterwards. Reading this list once a month takes two minutes and is the cheapest security control you have.
What to check
After inviting someone, confirm they appear as Active rather than Invited within a day. An invitation sitting unaccepted usually means the mail was filtered. After removing someone, confirm they are gone from Members and have no row left in Sessions.
Next
- Single sign-on — how sign-in works.
- Security and data protection — multi-factor authentication and the rest.
- Contacts and roles — the other set of people entirely.