Members and roles
| Role | Can |
|---|---|
| Member | Sign in, connect their own agents, see the organisation's audit log and posture. |
| Admin | Everything a member can, plus invite and remove members, change enforcement mode, enable frameworks, manage data labels and plan. |
| Super admin | Operate the platform itself. Not an organisation role. |
The person who creates an organisation is its first admin and can grant admin to others from the Members page.
Inviting people
Admins add members by email from Members. The invitee signs in, and the organisation appears in their account. Free organisations can have 5 members, Team 50, Enterprise unlimited.
Two-factor authentication
Every account can enable TOTP two-factor authentication from Settings: scan the QR code with an authenticator app, confirm a code, and keep the one-time recovery codes somewhere safe. Trusted devices can be remembered.
Agents belong to people
Each connected AgentShield is tied to the member who ran agentshield login. Removing a member disconnects their agents; the audit history they produced stays in the log.