> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mantle.chat/llms.txt
> Use this file to discover all available pages before exploring further.

# Members and permissions

> Invite people and understand who can view, create, and manage work.

Mantle uses organizations and workspaces to control access. An organization contains people and workspaces. Each
workspace has its own members and visibility.

## Organization roles

Organization owners and admins manage organization-wide settings, membership, billing, and workspace controls. Members
take part in the work they can access.

Use **Settings → Organization → Members** to invite or remove members and review their role. Select **Invite**, then:

1. choose **Member** or **Admin**;
2. review the workspaces they can access—the organization's default workspace is always included;
3. send an email invitation or create an invite link.

The person becomes an accepted member only after they use the invitation. Invite and wait for trial participants to
accept before starting a Plus trial.

In a self-serve paid organization, every accepted internal member needs a Core, Plus, or Max seat. The owner chooses
member levels in **Settings → Organization → Billing**. See [Plans and credits](/plans).

## Workspace roles

| Role                | What it is for                                                              |
| ------------------- | --------------------------------------------------------------------------- |
| **Member**          | Join conversations, create work, and use shared resources in the workspace. |
| **Workspace admin** | Manage members, settings, shared structure, and other workspace resources.  |
| **Owner**           | Full control of the workspace, including its most sensitive settings.       |

Some actions also depend on who created the item. For example, a regular member can manage the chats they created, while
an admin can manage shared workspace content more broadly.

## Public and private workspaces

* A **public workspace** can be found and joined by anyone in the organization.
* A **private workspace** can be opened only by invited members.

This setting does not publish content on the internet. Public links for chats and canvases are separate and must be
created explicitly.

## Invite people safely

You can add an existing organization member, send an email invite, or create an invite link. When using a link:

* choose a sensible expiry time;
* send it only through a trusted channel;
* replace it if it reaches the wrong person;
* give the lowest role the person needs.

Review workspace membership when a project ends or a teammate changes roles.

## Access to agents and connected apps

Agents belong to a workspace, so workspace members can use them. The agent's creator controls its execution settings;
workspace managers can manage its place in the workspace.

A shared agent does not give everyone the creator's app account. When a person runs an agent, Mantle uses that person's
available connection where required. A background task uses the connection set up for that task. See
[Integration access and safety](/integrations/security-and-delivery).

<Warning>
  Permissions reduce accidental access, but they do not replace good information handling. Keep highly sensitive
  material in the smallest suitable workspace and review public share links separately.
</Warning>
