One page that merges the code-defined owners with the invited staff rows, shows each person's role, invite state, last seen, and lets an admin invite, change a role, revoke with a mandatory reason, or reinstate. Sub-account owners never appear here — the vocabulary is enforced on purpose.
Also called: staff list · who works here · invite staff · revoke access · vendor employee list
- 1Owners come from source code and render read-only, with no controls at all.
- 2Staff are invited by email with a role; the invitation lands them on the panel once accepted.
- 3Status chips say what the state MEANS — 'Invite pending', 'Listed - no access' — rather than a bare word that reads as done.
- 4Role changes save inline; revoking opens a form because a reason is mandatory.
- 5Filters by role, status and search answer 'who holds admin?', which a card list alone cannot.
- 6The owner cannot be invited, demoted, revoked or written as a staff row — checked at three independent layers.
Straight from the page header: 'It exists because those things were previously only knowable by reading an environment variable, and when that variable drifted, a sub-account owner silently held administrative access to every other customer for weeks.' The invite-link rule carries its own bug code —: the first invitation ever sent carried a localhost URL because it came from the request origin on a dev machine.
- Access was configured in an env var that nobody could read or audit.
- Revocations happened without a recorded reason, so reviews had nothing to review.
- Invitation links could point at a developer's laptop.
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →