Membership has two levels. Someone joins an organization, then joins the workspaces within it. Adding them to one does not add them to the other.
Invite them to the organization
Either a username or an email address works. An email invitation reaches an account with that address registered — including as a secondary address, added with jstm profile emails add. Add them to the workspaces they need
owner, admin, member, or viewer.
Add people to the workspaces whose work they own, not to everything. Workspaces are the boundary for credentials as well as for agents.
Roles
Org-level administration — auditing credentials across every workspace, or changing a credential’s scope — requires owner or admin at the organization, not at a team.
Sharing an agent or run requires owner or admin in a team workspace; in an organization workspace, any role except viewer.
Changing a role
Promote to admin when someone needs to manage the team’s credentials, not merely to use them. member is enough to build, run, and operate agents.
Removing access
When someone leaves, remove them from the organization. Then check what they left behind:
The audit shows who connected each credential. A credential connected by a departing colleague will stop working when their access is revoked at the provider, so reconnect those under someone who is staying, or under a service account.
Agents built in a personal workspace leave with the person. If work matters to the team, it should live in a team workspace. Move it with jstm agent move.
Controlling who can join at all
OPEN lets organization members discover and join a workspace. RESTRICTED makes it invitation-only.
Bringing someone in around specific work
If you want to show someone a run or an agent rather than hand them a workspace, share it instead. Accepting a share adds them as a member and takes them straight to the object. See Share agents and runs.
See also