Organization roles
Everyone in your organization has exactly one organization role.
Billing exists for the person who handles invoices and usage while staying out of fraud data.
A new Member starts with zero project access. Grant projects during the invite, or their dashboard will be empty when they sign in.
Project roles
Project roles are granted per project. Someone can be an Editor on one project and a Viewer on another.
The line between Analyst and Editor follows what changes live traffic. An Analyst can build any custom list they like. Putting an account on Allow or Block is an Editor action, because it changes the decision your integration receives. The same reasoning splits editing a rule and turning it on into two separate permissions, so a custom role can allow one and hold back the other.
Custom roles
Admins can build their own project role from the same permission list. Start from Viewer, Analyst or Editor, then select the permissions the job needs. Custom roles sit alongside the built-in ones on the Roles tab and are assigned the same way. The Roles tab lists every role, its scope, and the permissions it covers. Use it as the reference when deciding what to grant. A role cannot be deleted while anyone still holds it, and a pending invitation naming it counts as well. Move everyone holding this role reassigns them in one step, which is usually what you want before deleting it. Deleting a role never removes access as a side effect of tidying up.Inviting a user
1
Open Settings → Team
The Members tab lists everyone in the organization, their organization role, and the projects they reach. Pending invitations appear here as well, marked Invited.
2
Enter the email and pick the organization role
Most people are Members. Choose Admin for someone who should manage projects and other people. Choose Billing for someone who needs usage and invoices only.
3
Grant the projects they need
Select each project and set the role for it. Select all with the role picker beside it applies one role across the whole list at once, which is usually what a new teammate needs. Custom roles appear in the same picker.Admin and Billing skip this step. Admins reach every project already, and Billing reaches none.
4
Send the invitation
The user receives an email invitation. Until they accept, they appear in the list as Invited with the roles they will get. Their access is live as soon as they accept.
Changing or removing access
Edit access reopens the same choices for an existing member. It replaces what they had, so clearing a project takes that project away from them. Select several people first and the same control changes them together. Anything left unticked stays as each person has it. Anything you do tick is replaced wholesale: everyone selected ends up with exactly the project access you chose. Remove takes the person out of the organization. To keep someone in the organization while cutting their access to data, set them to Member and clear every project. Pending invitations can be withdrawn from the same list.The Verisoul support account appears in your member list and cannot be removed. It is how we reach your account when you ask us for help.
MCP connections hold roles too
An AI client reaches your data through MCP access, either by a person signing in from the client or with a key. Both are bound by the same organization and project roles you set here. A sign-in is the person. It holds their role live, so changing their access changes what the client can do within seconds, and removing them from the organization ends the connection. A key holds a role exactly as a person does, so the same roles decide what it can do. Two things follow from that:- A key is created from the access of whoever creates it, and can only be narrower. Key creation therefore stays inside the limits you already set with roles.
- A key is retired when its creator’s access changes. Reduce someone’s projects, change their organization role, or remove them, and the keys they created stop working at the same moment.
Sandbox and Production are separate
Organization roles carry across both environments, and so does membership: someone in your organization is in it in both places, with the same organization role. Project grants work per environment, because Sandbox projects and Production projects are different projects holding different data. If you invite someone from Production and grant them two projects, they will find an empty dashboard in Sandbox until you switch environments and grant there as well.What only an Admin can do
- Create, rename, reorder and archive projects. An Editor works inside a project. Creating or retiring one is an Admin action.
- Manage the team: inviting people, changing roles, removing members. The Team screen is visible to Admins.
- View usage, which is also the one thing the Billing role provides on its own.
Troubleshooting
I granted access and the user still cannot see the project
I granted access and the user still cannot see the project
Check the environment first. Confirm the grant was made in the same environment the user is signed into. If both match, refresh the page. Role changes take a few seconds to apply.
A user is on the team but their dashboard is empty
A user is on the team but their dashboard is empty
They have an organization role with zero project grants, which is expected for a new Member. Open Edit access and select the projects they should reach.
A role will not delete, but nobody on the team holds it
A role will not delete, but nobody on the team holds it
An MCP key is holding it. Keys hold roles the same way people do, and they are listed under Settings → MCP access. A key cannot be moved to another role. If the client still needs access, create a replacement key, then revoke the old one and delete the role.
Someone's integration stopped working after I changed their access
Someone's integration stopped working after I changed their access
MCP keys are retired when the access of the person who created them is reduced or removed. If that integration needs to keep running, have someone who will keep the access create a new key for it.
A removed user was re-invited and lost their roles
A removed user was re-invited and lost their roles
A removed account comes back as a new user, so the previous roles stay behind. Grant their access again after they accept.
The Team page says it could not load the team
The Team page says it could not load the team
The Team page belongs to Admins. Someone who reached it through a saved link sees this message. Ask an Admin to make the change.
Our only Admin left the organization
Our only Admin left the organization
Contact support@verisoul.ai and we will restore admin access to the account.
