Members & roles

Invite teammates, assign the smallest useful role, and manage workspace ownership and access.

On this page

Workspace roles determine which data and actions a teammate can access. Open Members to review memberships and invitations. Current membership is checked by the server; hiding or showing a navigation item is not the authorization boundary.

Choose the right role

RoleMain responsibilitiesMDM access
OwnerFull workspace control, including ownership transferRead and operate when the MDM feature is enabled
AdministratorManage team, settings, policies, devices, and subscriptionRead and operate
Security managerInvestigate activity, review risks, manage policies and registered devicesRead-only
AuditorInspect security activity and export administrative auditRead-only
BillingView subscription and workspace usageNone
MemberConnect personal devices and view workspace informationNone

Owners and administrators can export audit data; auditors can export it too. Security managers can read the audit log but do not have export permission. MDM additionally requires its independent beta feature grant.

Invite a teammate

Use the Members invitation form with the intended email and permitted role. Share the generated private invitation link with its intended recipient using your approved channel. Treat the link as a credential. Pending, unexpired invitations consume allocated seats.

Allowed invitation domains are managed in Workspace. An empty restriction permits any domain. Tightening restrictions preserves existing members but revokes pending invitations outside the new boundary.

Change a role

An owner can manage role assignment. Administrators cannot assign or modify owner/administrator privileges through ordinary role changes; they manage lower-privilege roles. Use the ownership-transfer workflow when handing over the workspace rather than trying to remove the last owner.

Review the practical effect before changing roles: a security manager can change agent policy and registered devices but cannot send MDM actions; an auditor can export audit history but cannot review risks.

Remove access

Coordinate membership removal with device revocation and local offboarding. Check active device identities under Agents and verify remote revocation. Removing a browser session or uninstalling a CLI package does not by itself document all workspace access changes.

Consult the administrative audit trail after invitations, role changes, ownership transfer, and revocation. Preserve required evidence before deleting local data on a departing employee's device.

Platform administration is separate

Workspace ownership does not confer Beam platform staff access. Internal administration is deployment-controlled and separate from customer workspace roles. Use workspace roles for your organization, and contact Beam for hosted setup actions that require platform operations.

Explore the docs