3 Organizations and Workspace access
Portal is the source of truth for Organization membership, Teams, direct Workspace collaborators, and invitations. Use the Access page on each Workspace to understand who can open it and why.
3.1 Understand the scopes
An Organization contains its people, Teams, Workspaces, and billing. A Workspace contains the Nous experience, data, products, and Workspace-specific settings.
Organization and Workspace roles are separate:
| Role | What it grants |
|---|---|
| Organization owner | Manages Organization people and Teams, receives owner access to every Organization Workspace, and can create Workspaces in the hosted invite-only platform. |
| Organization admin | Manages Organization people and Teams and receives admin access to every Organization Workspace. It cannot create a Workspace in the hosted invite-only platform. |
| Organization member | Belongs to the Organization but receives no Workspace access automatically. A direct grant or Team grant is required. |
| Workspace admin | Manages one Workspace. This role does not grant authority over Organization people or Teams. |
| Workspace collaborator | Uses one Workspace without Workspace administration rights. |
Always include the scope when assigning an admin role. An Organization admin and a Workspace admin have different authority.
3.2 Manage Organization people
Organization people and Teams share one page, People & Teams, with two segments, Teams and People. It is available to Organization owners and Organization admins only. Every other member gets no entry for it and no page: Portal is the administration console, and a member’s Organizations list shows their member and Team counts as plain text rather than links.

On a narrow screen the same page keeps each Team’s name and member count and drops the columns that do not fit; the Workspace and knowledge-source counts stay on the Team’s own page.

- Open Organizations in Portal and select the Organization.
- Open People & Teams and select the People segment.
- Click Add people.
- On Invite by email, type a name or an email address. People already in the Organization are offered from the list; any other address becomes a new invitation.
- Choose Member or Admin on each selected person’s own role control. Someone who is already in the Organization is marked Already in organization and has no role control here; change their role from the roster instead.
- Click the button that names the outcome, such as Invite 3 people or Add 3 people.

To add many people at once, use the Import a file tab. Choose a .csv or .xlsx file with one email address per row in the first column, or click Download template to start from the expected shape. Portal accepts up to 100 addresses in one batch and skips blank, repeated, and unusable rows instead of rejecting the file, reporting how many it skipped. Every imported address still gets its own role control before you submit.
The People segment lists the active members, with a Pending invitations section under the roster. An Organization invitation can also carry Workspace access, and such an entry carries an Also grants line naming each Workspace and Team it carries.
The roster also shows an Added column, the date the person was added to the Organization, and a Workspaces column, listing which Workspaces the person can reach. An Organization owner or admin reaches every Workspace, so that row reads All workspaces instead of listing them one by one. A member’s row lists the Workspaces reached through a Team or a direct grant, and is empty when the member has no Workspace access yet.
A Workspace filter sits above the roster next to the existing search box and Team filter, narrowing the list to people who can reach a chosen Workspace. Clear filters resets all three at once.
Export to Excel downloads the roster as an .xlsx file. The download includes everyone who matches the filters currently applied, not only the rows visible on the page, and the export is recorded in the Organization’s audit trail.
An invitation stays in Pending invitations until it is accepted or revoked, including after it expires. An expired invitation shows the Expired state instead of Pending, and active invitations are listed first.
Portal also closes an invitation on its own, in one case: when the person it names already holds everything it would grant. That happens when access arrives by another route, such as making them an Organization owner or admin, adding them to a Team that already has the Workspace, or granting the Workspace directly. There is then nothing left for the invitation to give, so Portal revokes it, stops offering Resend, and sends no further email about it. The entry leaves Pending invitations without anyone having accepted it, and the closure is recorded in the Organization’s audit trail. An invitation that carries more than the person already holds is untouched and stays listed, resendable and revocable.
An Organization owner or Organization admin can use Resend and Revoke on any listed invitation, expired ones included, and can change an active member’s Organization role. The owner role is the exception: only an Organization owner can make somebody an owner, change an owner’s role, or remove an owner. An Organization admin manages admins and members, and on an owner’s row the role is shown as plain text with no Remove, with the reason on hover. Nobody can change or remove themselves, so an Organization always retains at least one owner. To hand over ownership, make the other person an owner first, and they can then remove you. Revoke asks for confirmation first and names the Workspace access and Team membership the invitation carries, because revoking withdraws all of it and not only the Organization membership.
Bulk actions build on the same roster. Each row carries a checkbox, and a header checkbox above the table selects every row on the page at once. Some rows are left out of that selection because they cannot be acted on, and the checkbox says why on hover: you cannot select yourself, and an Organization admin cannot select an owner’s row, only an Organization owner can.
Selecting one or more people opens a bar above the table naming how many are selected, with a Change role to… control and Remove. Change role to… offers Member and Admin, and Owner only when the signed-in person is an Organization owner, the same rule the roster already applies row by row. Remove asks for confirmation first, naming how many people are about to leave the Organization and listing them.
A bulk action on the People roster is all or nothing: if anything in the selection cannot go through, nothing at all changes, and the message names the people to unselect before trying again. There is no partial result to untangle. The selection itself clears whenever the underlying list changes, on a page turn, a filter change, or once an action completes, so it can never end up naming somebody the roster no longer shows.
Resend gives the invitation a new expiry date and sends a fresh email. Inviting the same address again reaches that same invitation instead of creating a second one. Portal sends another email when something about the invitation has to change, such as an expired invitation or a different role, and sends nothing when the invitation is already current. The confirmation reads the same either way, so use Resend when you need to be certain that an email went out. After a send, Resend is unavailable for a short period and states when it becomes available. That period is longer when Portal could not confirm what became of the email: the invitation is saved, and the confirmation reports the delivery as unconfirmed rather than as a success or a failure, because an email that may already have arrived must not be sent a second time. Inviting the address again or using Resend while that longer period is still running names the same wait.
Bulk actions are available on Pending invitations as well. Each entry carries a checkbox, the checkbox above the list selects every listed invitation at once, and selecting one or more opens a bar naming how many are selected, with Resend and Revoke. Revoke applies to the whole selection or to none of it, the same way the People roster’s bulk actions do: if one selected invitation cannot be revoked, nothing is revoked, and the message names the invitations to unselect before trying again.
Resend reports each invitation on its own, because it sends an email and an email that has already gone out cannot be taken back. One action can therefore report some invitations sent, some still inside the wait that follows their last send, some whose email Portal could not confirm, and some changed since the page was loaded, such as one that somebody else has already resent or revoked. Read the result rather than assuming that every selected invitation went out; an invitation still inside its wait can be resent once that wait elapses. Resend covers at most 25 invitations in one action, because each one is an email to a person. Select more than that and Resend turns unavailable and says so, rather than letting you confirm a send that would be refused; Revoke stays available, up to 100 at a time.
A search box above Pending invitations narrows the list by email address, the same way the search box above the People roster does. It also narrows what the checkbox above the list selects, so select all means the invitations you can see and nothing else, and changing what you search for clears the selection rather than leaving it holding invitations the list no longer shows.
3.3 Invite direct Workspace collaborators
Use a direct grant when one person needs access to a specific Workspace without broader Organization membership.
- Open the Organization and find the Workspace card.
- Click Access.
- Click Invite collaborators.
- Enter one or more email addresses, up to 20 in a single batch.
- Choose Member for a Workspace collaborator or Admin for a Workspace admin.
- Click Send Invites.
Pending Workspace invitations appear on the same Access page and stay listed after they expire, with the Expired state. A Workspace admin can revoke them, expired ones included, and can change their role the same way. Resend is available on most entries; the two entries further down that withhold it say so and explain why. Resend issues a new email and a new expiry date, and is unavailable for a short period after each send. As on the Organization People & Teams page, that period is longer when Portal could not confirm what became of the email. Such a send still gives the invitation its new expiry date, and is reported as unconfirmed rather than as a success or a failure; using Resend again before the period elapses names the wait instead.
Each kind of email keeps its own wait. The Organization email and the Workspace email are sent separately, so a wait shown on one entry does not silence the other. Someone you add to an Organization and to a Workspace within the same few minutes therefore receives both emails. Both carry the same invitation, so accepting either one is enough.
To change the role on a listed Workspace invitation without inviting the address again, choose the role from the control on that entry. The new role applies when the invitee accepts. Changing it sends no email and does not change the invitation’s expiry date.
Workspace invitations differ from Organization invitations in one way. Inviting an address that already holds a listed Workspace invitation never sends a new email, not even when that invitation has expired; Portal reports the address as already invited instead. If the role you choose differs from the role on the listed invitation, the invitation takes the role from the new batch, whether that raises it to Admin or lowers it to Member, and the confirmation message names the change. Use Resend for those, or revoke the invitation and then invite the address again. Revoking and inviting again produces a new invitation only when the invitation carries nothing beyond this Workspace: one that still carries active access to another Workspace, or that also carries Organization membership, stays pending after you revoke its Workspace access. Inviting the address again then restores that access on the same invitation instead of sending a new email.
One entry behaves differently. A single invitation can grant both Organization membership and Workspace access, which happens when someone holding a pending Workspace invitation is then invited to the Organization. That entry is marked Organization invitation.
Resend on such an entry resends the Organization invitation, exactly as it would on the Organization People & Teams page: it applies the Organization expiry period and sends the Organization email, because that is what the recipient accepts. It is therefore offered only to Organization owners and admins. A Workspace admin who does not hold one of those roles sees no Resend on that entry, and a note under the list says so; managing a Workspace does not confer authority over Organization membership.
Everything else on the entry is Workspace work and is available to any Workspace admin. Changing the role is managed here, because the role belongs to the Workspace access rather than to the Organization membership. Revoking here withdraws only the Workspace access; the Organization invitation stays pending on the Organization People & Teams page, and the entry is removed from this Access page. Inviting the same address to this Workspace again restores the Workspace access on that same invitation, and the confirmation message names the restoration and the role the address now holds. Both the revoke and the restoration are recorded in the Organization’s audit trail.
A second entry withholds Resend, and it is marked Sent from another account. It appears when a Workspace has changed hands: invitations sent before the move still carry access to the Workspace, but they belong to the account that sent them, and only that account can resend one. A note under the list says so. Changing the role and revoking remain available, because both act on this Workspace’s own access. Revoking such an entry withdraws that access and nothing else; when the invitation carried no other access, it is closed as well, and that closure is recorded in the audit trail of the account that sent it rather than in yours.
The invitee must open the invitation, sign in with the invited email, and click Accept invitation. Opening the link without accepting it does not grant access.
3.4 Use Teams for repeatable access
A Team groups active Organization members. Team membership has no role by itself. The role is assigned when the Team receives access to a Workspace.
To create and grant a Team:
- Open the Organization and open People & Teams, which opens on the Teams segment.
- Click Create team, give it a recognizable name, and add a description if it helps. The description is optional. Team names are unique inside an Organization regardless of capitalization, so a second
Financeis refused rather than merged into the first. - Open the Team, and on Members click Add members. This uses the same dialog as the Organization, with the same Invite by email and Import a file tabs. Someone added to a Team who is not yet in the Organization joins it as an ordinary Organization member; a Team never grants an Organization role.
- Open Access and select a Workspace under Workspace access.
- Choose the Member or Admin role and click Grant. To change an existing grant, choose the new role on its entry, or select the Workspace again and click Update.

A Team has four tabs:
- Members holds the people on the Team and the Team’s own invitations.
- Resources is read-only. For each granted Workspace it lists the Connectors, Projects and Document Sets that Workspace shares with the Team, with an Open connectors link into the Nous screen where they are managed, and the Digital employees in the Workspaces the Team can reach. A kind with nothing in it says so rather than disappearing, so an empty list and a missing one never look the same.
- Access is the only place where the Team’s Workspace grants are made, changed, and revoked.
- Settings holds the Team name and description, and Delete team.
Deleting a Team removes it for everyone and revokes the access it grants. Members keep their accounts, and access they hold through another Team or a direct grant is unaffected. The confirmation names the Team and counts the memberships and Workspace grants it is about to withdraw. There is no restore, so re-create the Team and grant it again if you need it back.
Digital Employees attached to a Team inherit that Team’s Workspace knowledge access. The Team’s Resources view shows this inherited knowledge as read-only. Revoking the Team’s Workspace grant denies access to attached employees, but does not change their lifecycle. Regranting the Team’s Workspace access restores their access. Portal blocks Delete team until every attached Digital Employee is fully deleted.

Every active Team member receives the Team’s role for that Workspace. A Team can have different roles in different Workspaces. When someone must accept an invitation before becoming an active Team member, the Members tab shows a Pending invitations control with the number waiting, and opens that list in a dialog. The control is absent when nothing is pending.
Team invitations behave like Organization invitations. An expired one keeps its place in the list with the Expired state, stays resendable and revocable, and is refreshed and sent again if you add the same address to the Team a second time.
Use Teams when access follows a stable business group, such as Legal, Finance, or Customer Support. Use a direct grant for an exception that applies to one person.
3.5 Review effective access
The Workspace Access page contains three areas:
- Teams with access lists Teams that grant a Workspace role.
- People with direct access lists direct grants and Workspace invitations that have not been accepted, including expired ones.
- Effective access lists everyone who can currently open the Workspace and the source of that access.
A person can have several active sources at once:
- Organization authority
- A direct Workspace grant
- One or more Team grants
Portal uses the highest active role across those sources. The order is owner, then admin, then member. A direct Member grant does not reduce an Admin role received from the Organization or a Team.
Before removing access, review the person’s source badges in Effective access. Removing a direct grant does not remove a Team or Organization grant. Removing someone from one Team does not remove access granted by another Team.
3.6 Change or remove access safely
Choose the action that matches the source:
| Access source | Where to change it |
|---|---|
| Organization role | Organization People & Teams, People segment |
| Direct Workspace grant | Workspace Access |
| Team membership | Organization People & Teams, then open the Team and use Members |
| Team-to-Workspace role | Organization People & Teams, then open the Team and use Access |
| Pending Organization invitation | Organization People & Teams, People segment |
| Pending Workspace invitation | Workspace Access |
| Pending invitation that also grants Organization membership | Workspace Access for the Workspace role and to withdraw Workspace access. Resending is available on either Workspace Access or Organization People & Teams, to Organization owners and admins only |
After a change, return to Effective access to confirm the result. Access changes can show a short synchronization state before they are available in Nous.
3.7 Management access and document access are different
Workspace roles control who can enter and administer a Workspace. They do not automatically make every private connector, document set, Project, or other shared resource searchable.
Use the sharing controls for each resource to choose Everyone in this Workspace, a named Team, or another supported private scope. This separation lets a Workspace admin manage the Workspace without silently receiving access to every private document.
See Connectors for connector document access and Team sharing.