← Back to documentation

Organization Member Management

Manage organization access, roles, ownership, invitations, and member removal.

6 min read

Use this guide for the organization administration.

Purpose#

Use this guide to:

  • Activate organization mode.
  • Invite members and select their roles.
  • Change a member role.
  • Transfer the organization ownership.
  • Send an invitation again, or revoke it.
  • Remove members.

Before you start#

  • You must have the Owner role or the Admin role to use Member Management.
  • A user in personal mode must activate an organization first.
  • Team organizations are available on the Team trial, the Team plan, the Scale plan, and an eligible custom plan. Sandbox and Solo are single-user plans.
  • The member limit comes from the plan. Sandbox and Solo permit 1 active member. The Team trial and Team permit 5. Scale permits an unlimited number of members. For a custom plan, the agreement of the organization sets the member limit.
  • An account belongs to one organization for its complete life. You can invite a new email address, and you can restore a removed member of the same organization. An invitation cannot claim an active account or an account in a different organization. Invite your teammates before they sign up as individuals. See Inviting someone who already signed up.

Roles:

  • Owner (OWNER): can do all the Admin actions and the owner-only actions, such as a change of the billing contact email address, an ownership transfer, and the closure of the organization.
  • Admin (ADMIN): can manage the members, the invitations, the billing, the audit log, the organization name, the endpoints, and the targets.
  • Member (can edit) (USER): can create and manage the delivery configuration, but cannot manage the organization members.
  • Viewer (read-only) (VIEWER): can see the shared resources, but cannot change the organization configuration, the endpoints, the targets, or the members.

Procedure#

1. Activate organization mode (if needed)#

  1. Open Settings -> Organization.
  2. Create or activate an organization with a unique name.

After the activation, Organization and Member Management become available. If the current plan does not include team organizations, start the Team trial or upgrade to Team or Scale.

2. Open member management#

  1. Open Organization.
  2. Select Open member management. This control is for admins only.

3. Invite a member#

In Invite member:

  1. Enter the email address.
  2. Enter a name. This is optional.
  3. Select Member (can edit), Admin, or Viewer (read-only).
  4. Select Send invitation.

Rules:

  • The email address must be valid. If the address is registered already, you can invite it again only when the account is inactive and PayloadRelay removed it from this organization. PayloadRelay rejects an active account, an account that waits for deletion, and an account in a different organization.
  • An invitation link expires after 7 days.
  • OWNER is not available as an invitation role. Use the ownership transfer after the member joins the organization.
  • A pending invitation counts against the member limit of the plan.

4. Update member roles#

  1. Find the member in Organization members.
  2. Change the role with the role selector.

Guardrails:

  • The organization must always keep one active admin-like member as a minimum (OWNER or ADMIN).
  • You cannot lower the role of the current owner directly. Use the ownership transfer flow.
  • You cannot change a removed member.

5. Transfer ownership#

Only the current owner can transfer the organization ownership.

  1. Find an active Admin or Member (can edit) in Organization members.
  2. Select Transfer ownership.
  3. Approve the request in the email that PayloadRelay sends to the email address of the current owner.

After the approval, the current owner becomes ADMIN, and the selected member becomes OWNER. You cannot transfer the ownership to your own account, to a removed member, to a VIEWER member, or to the current owner.

6. Manage pending invitations#

In Pending invitations:

  • Resend creates a new token and a new email.
  • Revoke makes the invitation invalid.

You cannot revoke an accepted invitation.

For each address, PayloadRelay sends one invitation email in two minutes, and three in one hour. Your organization also has a limit of 30 in one hour, and the relay target confirmation emails use the same limit. PayloadRelay refuses an invitation or a resend that is more than a limit, and it changes nothing. If PayloadRelay refuses a request, wait and send it again.

7. Remove members#

Use Remove on an active member.

Guardrails:

  • An admin cannot remove their own account.
  • You cannot remove the last active admin-like member (OWNER or ADMIN).
  • You cannot remove the owner directly. Transfer the ownership first.
  • A removed member becomes inactive and loses the active sessions. The historical resource ownership and audit ownership of that member stays.
  • To restore a removed member in the same organization, send a new invitation to the same email address. When the member accepts, the existing account becomes active with the invited role and a new password.

Expected result#

  • Each invitation appears with its role, its status, and its expiry date.
  • A member who accepts an invitation appears in Organization members with the assigned role.
  • The role actions and the invitation actions stay after a page reload.
  • The ownership transfer stays pending until the current owner approves it in the email.

Common issues and fixes#

  • "Admin or owner access required": ask a current admin or owner for an admin role or an owner role.
  • An invitation conflict: the address has an active account, waits for deletion, belongs to a different organization, or has a pending invitation already. See the next section.
  • To restore a removed member: invite the same email address again. You cannot claim an address from an active account or from a different organization.
  • The invitation expired: send the invitation again to create a new token.
  • The role change is disabled: the member is the owner or a removed member, or the role change leaves no admin-like member.
  • The remove action is disabled: the member is your own account, a removed account, the owner, or the last admin-like member.

Inviting someone who already signed up#

An active account is bound to one organization permanently. You cannot add an existing active account to your organization. This occurs when a colleague signs up before the team organization exists. A removed member of your organization is the exception. To invite that account again, use the restoration flow in this guide.

You cannot merge or move an active account. Use this process:

  1. The account holder closes the account in Settings -> Security, in the danger zone at the bottom. A user in personal mode closes the account here. The Organization tab gives the organization closure only after the organization activation.
  2. The account enters a 30-day recovery window. You still cannot invite the address in this period.
  3. After the window ends and PayloadRelay deletes the account completely, invite the address again in the normal way.

PayloadRelay deletes the endpoints, the relay targets, and the Activity history with the account. PayloadRelay does not move them to your organization. Ask the account holder to record the endpoint configuration before they close the account.

If the recovery window causes a problem, contact Support. An operator can do a confirmed erasure after a direct conversation with the account holder.