# Teams and roles

> Create a team organization on Tokens, invite members, give them a role and a monthly spending cap, switch between organizations, and remove a member. Includes what each role can do and what a team shares.

An organization lets several people work under one Tokens account: shared keys and usage reporting, a role for each person, and a monthly spending cap for each member. This page covers creating a team, inviting people, what each role can do, spending caps, switching between organizations and removing a member.

:::note[Teams may not be enabled for your account]
Teams are a feature that Tokens switches on per deployment. When it is off, the **Team & members** item is missing from the dashboard sidebar and the organization switcher is hidden. If you open [/dashboard/team](/dashboard/team) anyway, it says "Teams and collaborative workspaces are coming soon." Ask [support](/docs/support) if you need it.
:::

## Personal and team organizations

Every account has a **Personal** organization, created automatically. Your keys, plan and wallet live there until you create a team. A personal organization has no members to invite: **Invite Member** is only shown in team organizations.

A **Team** organization is one you create. You become its **owner**. Everything below happens in the organization that is active in the switcher, so check the name and the Team or Personal tag in the top bar before you create a key or invite someone.

## Create a team

1. Open the organization switcher in the dashboard top bar.
2. Press **Create Team Organization**.
3. Enter the **Team / Organization Name** and press **Create Team**.

The dashboard reloads with the new team active and you as its owner. Open [/dashboard/team](/dashboard/team) to manage it. Owners and admins can also open **Org Settings** there to change the **Organization Name**, **Billing Email (Receipts)**, **Company / Legal Name** and **BIN / VAT / Tax ID**.

## Invite members

Invitations are links. Tokens does not email them for you.

1. In the team organization, open [/dashboard/team](/dashboard/team) and press **Invite Member**.
2. Enter the **Email Address**, choose a **Role** and optionally a **Monthly Spend Cap (Optional USD)**.
3. Press **Generate Invitation**.
4. Copy the **Invitation Link (valid for 7 days)** and send it to the person yourself.

The invited person opens the link while signed in to a Tokens account that uses the same email address, and presses **Accept and join organization**. A link issued to one address does not work for another one: the error says which address the invitation was issued to. After joining, they open the organization switcher and choose the team to start working in it.

Things that can stop an invitation:

- **Seat limit.** The number of members comes from the plan active on the organization. Without a plan, the limit is 1, which is the owner. Past the limit, you get "Organization has reached its plan seat limit of N members. Upgrade your plan to invite more team members." Pending invitations count towards the limit until they are accepted or expire.
- **Already a member.** "This user is already a member of the organization".
- **Expired or used link.** Generate a new invitation.

:::tip
Set the member's spending cap in the members table after they have joined, and check that it shows there. See the section on per-member spending caps below.
:::

## Roles and what each can do

There are five roles. The first four can be chosen when you invite someone or change a role; the owner is the person who created the team.

| Action                                   | Owner | Admin | Billing | Developer | Viewer |
| ---------------------------------------- | :---: | :---: | :-----: | :-------: | :----: |
| See the member list                      |  Yes  |  Yes  |   Yes   |    Yes    |  Yes   |
| See the usage table for all members      |  Yes  |  Yes  |   Yes   | Own row only |  Yes   |
| Create API keys                          |  Yes  |  Yes  |   No    |    Yes    |   No   |
| See keys in the organization             |  All  |  All  |  None   | Own keys  |  None  |
| Rotate or revoke keys                    |  Any  |  Any  |   No    | Own keys  |   No   |
| Invite members, change roles, set caps   |  Yes  |  Yes  |   No    |    No     |   No   |
| Remove members                           |  Yes  |  Yes  |   No    |    No     |   No   |
| Edit Org Settings                        |  Yes  |  Yes  |   No    |    No     |   No   |

The invitation form describes the roles like this:

- **Developer**: "Create & manage own keys, view own usage".
- **Admin**: "Manage members, keys, view all usage".
- **Billing**: "Manage subscription & top-ups, invoices".
- **Viewer**: "View org usage & models, read-only".

Limits on admins:

- An admin cannot change another admin's role, and cannot remove another admin.
- An admin cannot set a spending cap for themselves or for the owner.
- Nobody can demote or remove the owner from the dashboard. The role list for a member has Admin, Billing, Developer and Viewer only.

Billing and viewer members cannot create keys and see no keys, so they cannot run requests in the team. In the [playground](/docs/playground) they see "No active API keys found" for the team.

## Per-member spending caps

A cap limits how much one member's requests can spend in a calendar month. Set it in the **Monthly Spend Cap** column of the members table (in dollars), or leave it blank for no cap. The table saves when you leave the field.

How it is enforced:

- Tokens adds up what that member has spent in the team since the start of the month, plus requests still running, plus the most the new request could cost. If the total would pass the cap, the request is refused before it reaches the model.
- The refusal is `402 member_cap_reached`. The message tells the member to ask the organization administrator to raise the limit. It is listed in [Errors](/docs/errors).
- The cap is per person, not per key. Individual keys can also have their own monthly cap; both are checked. See [API keys](/docs/api-keys).
- A cap of 0 is treated as no cap. Use a small positive number to block a member.

The **Usage by Member (Current Month)** table on the same page shows each member's requests, total tokens, month spend in USD and cap.

## Switch between organizations

Use the organization switcher in the top bar. It lists every organization you belong to, with a check mark on the active one. Choosing another one reloads the dashboard. Keys you create, usage you see and the team page all follow the active organization.

You can belong to several teams at once and keep your Personal organization as well.

## What is shared and what is not

Per organization, shared by its members:

- **API keys.** A key belongs to the organization it was created in. Which keys you can see depends on your role (see the table above).
- **Usage records.** Every request is recorded against the organization and the member who made it. The usage-by-member table on the team page reads from them.
- **Funding.** Requests made with a team key are charged against the wallet and plan of the organization the key belongs to. The invitation page says members issue keys "funded by the organization's credit pool".

Not shared:

- **Your Personal organization.** Its keys, plan and wallet stay yours and are not visible to the team.
- **Your profile, email and sign-in.** Teammates see your name and email in the member list and nothing else.
- **Referral earnings.** They are paid to your own wallet. See [Referrals](/docs/referrals).

:::warning[Check the funding before you roll out]
The seat limit and the team's funding come from the plan and wallet attached to the team organization, not from your personal ones. Before inviting a whole team, make a test request with a team key and check that it is charged as you expect, or ask [support](/docs/support) how your team is funded.
:::

## Remove a member

Owners and admins can press **Remove** on a member row. A confirmation dialog titled "Remove Team Member" warns: "All API keys created by this member will be permanently revoked immediately." Press **Confirm & Revoke Keys** to continue.

When you remove someone:

- Every active key they created in this organization is revoked at once. Tools using those keys get `401 invalid_api_key` on the next request.
- They lose access to the team's keys, usage and settings.
- Their own account and Personal organization are untouched. If the removed team was their active organization, they are moved back to their Personal one.

If you want to keep a key a member made, create a new key yourself first and move your tools to it. Revoked keys cannot be restored.

## Related

- [API keys](/docs/api-keys)
- [Usage, limits and alerts](/docs/usage-and-alerts)
- [Plans, credits and wallet](/docs/plans-and-wallet)
- [Dashboard tour](/docs/dashboard-tour)

---
Page: https://tokens.bd/docs/teams-and-roles
