Manage members and accounts
Who: organization owners and administrators. Where: Administration → Members.
Invite a member
Enter the member details
Enter the member's email address, choose an appropriate role, and select Invite member. Verify the email carefully before submitting.
Share setup instructions securely
If an account-setup link is returned, copy it while displayed and send it through an approved secure channel. Do not assume that the application automatically delivered that link to the recipient.
Have the member finish setup
Ask the member to set a password, verify their email, and follow the organization's MFA policy. They can then sign in.
For an existing identity in the configured tenant, the UI may report that the account was added without returning a new setup link. Do not treat that as support for using one account across organizations.
Change role or revoke access
Choose the intended Role and Status, then select Save on the member's row. The current membership statuses are ACTIVE and REVOKED; Suspended is no longer offered in the account-lifecycle implementation covered here.
| Action | Result | Can the email be onboarded elsewhere? |
|---|---|---|
| Set status to REVOKED | Blocks membership access while retaining the membership and identity account. | Revocation alone does not release the account for another organization. |
| Set status to ACTIVE | Re-enables a retained membership, subject to the account's other requirements. | This is not an organization transfer. |
| Remove account | Deletes the tenant Firebase user and current membership, removes group membership and direct catalog grants, and clears identifying fields on the retained identity record. | After successful cleanup, the email can be onboarded to another organization as a new account. |
Permanently remove an account
This feature requires the account-removal release. It is destructive and cannot be undone through the confirmation dialog. It does not move the user's work to a new organization or promise complete erasure of every audit record and historical artifact.
- Confirm the exact member and arrange continuity for their responsibilities.
- If they are the only active owner, appoint another active owner first.
- Select Remove account, read the confirmation, then select Remove account permanently.
- Wait for confirmed success and refresh the member list.
- Only after removal completes, ask the destination organization's administrator or operator to onboard the email again. The new account must complete setup and that organization's MFA requirements.
The cleanup retains a terminated, anonymized identity record for historical references. It deletes the Firebase user within the organization's tenant, not the person's Gmail or Google account, and it does not delete the tenant itself.
If removal fails
The backend stages revocation before deleting the provider account. A provider failure can leave the account blocked while cleanup remains incomplete. Ask the administrator/operator to inspect and retry the removal; do not assume the email has been released.
Tenant mismatches and legacy identities with multiple memberships are rejected for remediation. Do not manually change identity IDs or disable membership checks to work around this.