Members and invites guide
How to invite humans into the company without confusing user access with seat accountability.
Inviting a human gives them access to the company. Staffing a human into a seat gives them accountability for a function. Keep those two ideas separate.
Invite first, staff second
Invite the person as a tenant member. Then assign them to one or more seats only after each seat has a clear purpose and Charter. A founder or operator may occupy several seats early in setup.
Roles and seats
Tenant roles control app access. Seats control operating accountability. Do not attach goals, tasks, or measurables directly to a user when the work belongs to a seat.
Owners and admins can invite people and manage member roles. Use external_implementer plus setup-limited access for a temporary implementation partner helping configure onboarding, Responsibility Graph, Compass, Charters, and agent setup. Setup-limited access is intentionally not enough for sensitive operating surfaces: Settings member/invite/token/runner/credential metadata, run and tool-call history, runner diagnostics, integration metadata and tests, system health, and owner/operating pages require owner/admin or full setup access. Scorecard (Signal) and Issues (Friction) reads are the exception: every active member can open them, scoped by the tenant member-visibility mode — either every member sees all Signals and Frictions, or each member sees only the seats they occupy plus everything downstream. Write actions on those pages stay role-gated. Do not grant external implementers sensitive run history, hidden tool arguments, credentials, Memory, or company-operating data unless an owner explicitly expands their profile.
Working across several client companies
An implementer invited into more than one client company sees a company switcher in the app sidebar; it always shows the active company so it is clear which client you are working in, and lets you switch between the companies you have an active membership in. Switching is validated against your memberships server-side — you can only enter a company you are an active member of, and a company you have been removed from disappears and can no longer be opened. Switching changes which company is active; it never grants access you were not given in that company. From the CLI or an agent session the same operation is rost use (validated by user.use_tenant).
Agent guidance
When a user asks to add a person, clarify whether they mean app access, seat occupancy, or both. Use invites for access and staffing commands for occupancies.