Skip to main content
Administration and Security

Team administration

How administrators manage the team of an Ottili ONE company: invite members, assign roles, control status, suspend, reactivate and remove them — plus security best practices.

Overview

Team administration* is the ongoing operation of a company's team in Ottili ONE. Where [Company administration](/docs/company-administration) covers master data, ownership and tenant isolation, this article describes the member lifecycle: inviting, assigning roles, controlling status, suspending, reactivating and removing members.

Team members are managed via Settings → Team* in the [Ottili Console](https://ottili.one/console). Team management shares the same Ottili Auth login and the same company context as the [Workspace](https://dashboard.ottili.one). Only members with the Owner* or Admin* role see the full team administration functions.

Opening the team

1. Sign in via [Ottili Auth](/docs/account-and-login).

2. In the top bar, open the company switcher* (building icon) and choose the target company.

3. Go to Settings → Team*.

There you see every member of the company, their role and status, plus actions to invite, change and remove members. For a tour of the interface, see [Navigate Ottili Console](/docs/navigate-ottili-console).

Inviting members

Only Owner* and Admin* may invite team members. The full flow — from the invitation email through role selection to acceptance — is described in [Invite a team member](/docs/invite-a-team-member).

Short version:

1. Open Settings → Team*.

2. Click Invite member*.

3. Enter the email address*.

4. Choose the role* for the new member.

5. Click Send invitation*.

The invited person receives an email with a personal invitation link. Through that link they accept the invitation and are associated with the company.

Member status

Every member has a status that reflects their access:

StatusMeaning
Active*Full access according to the assigned role.
Invited*Invitation sent, not yet accepted (pending).
Suspended*Access temporarily removed; the account is retained.
Removed*No longer has access to the company; membership ended.

Invitation lifecycle

An invitation moves through clear stages:

  • Pending* – sent, not yet accepted.
  • Accepted* – the person has joined the company.
  • Expired* – invitation links are time-limited and expire after 7 days*.

If an invitation has expired or was not delivered, resend it from Settings → Team*. A new invitation replaces the old one and restarts the 7-day window.

Assigning roles

Access is controlled by five roles, each bound to permissions:

RoleScope
Owner*Full control — billing, modules, settings, team. At least one Owner is always present.
Admin*Invite members, manage access, modules, settings and approvals.
Manager*Manage CRM, inventory and automation workflows without changing company-wide settings.
Employee*Work within the modules without changing company-wide settings.
Viewer*Read-only access to company data and modules.

Only Owners and Admins may change roles. Assign the lowest role that fits the tasks. The complete permission model is described in [Roles and permissions](/docs/roles-and-permissions).

Changing roles and access

To change a member's role or status:

1. Open Settings → Team*.

2. Select the member.

3. Change the role* via the role menu (requires Owner or Admin).

4. Save the change.

The new role takes effect immediately: from then on the member sees only the modules, data and actions that match their role. Active sessions are aligned to the new permission scope.

Suspending and reactivating members

Suspend access when a member should temporarily lose permission but keep their account — for example during leave, parental leave or a transition in progress:

1. Open Settings → Team*.

2. Select the member and set the status to Suspended*.

A suspended member can no longer sign in; their data and associations are retained. Through the same path you set the status back to Active* and reactivate access.

Removing members

Remove members as soon as they leave the company, so no access remains:

1. Open Settings → Team*.

2. Select the member and remove them from the company.

A removed member loses access immediately. The associated records and activities remain in the company context so that history and audit logs stay complete. This action is available only to Owners and Admins.

Team security

Good team administration is a central security lever:

  • Enable two-factor authentication (2FA/MFA)* for all members with elevated access.
  • Least privilege*: assign the lowest fitting role and review roles regularly.
  • Remove former members promptly* once they leave the company.
  • Monitor the approval queue*: sensitive, externally directed or risky actions go through the [Approval queue](/docs/approval-queue) and require human approval.
  • Keep Ottili Auth as the single identity provider* — passwords, sessions and MFA are validated centrally there.

Details on account protection, tenant isolation and audit logs are in [Account and data security](/docs/account-and-data-security).

Best practices for team administrators

  • Invite only people you trust.
  • Assign roles by responsibility, not by hierarchy.
  • Review regularly: who has access, and is the status still correct?
  • Cancel pending invitations that are no longer valid.
  • Remove former members' access promptly.
  • Enable 2FA/MFA for all members with elevated access.

Troubleshooting

Invitation not received

  • Check that the email address was entered correctly.
  • Ask the person to check their spam or junk folder.
  • Resend the invitation from Settings → Team*.

Invitation expired

  • Invitations expire after 7 days.
  • Send a new invitation to restart the process.

Role cannot be changed

  • Only Owners and Admins may change roles — check your own role in the current company context.
  • Make sure you are working in the correct company (company switcher).

Suspended member cannot sign in

  • This is the expected state of a suspension. Set the status back to Active* via Settings → Team* to reactivate access.

Related articles

  • [Company administration](/docs/company-administration) – master data, ownership, tenant isolation.
  • [Invite a team member](/docs/invite-a-team-member) – the full invitation flow.
  • [Company and team](/docs/company-and-team) – basics of company, team and switching.
  • [Roles and permissions](/docs/roles-and-permissions) – the complete permission model and AI scope.
  • [Account and data security](/docs/account-and-data-security) – account protection, tenant isolation and audit logs.
  • [Approval queue](/docs/approval-queue) – human approval of sensitive actions.

Was this article helpful?