Skip to content

Membership Management#

Membership management lets a workspace owner invite other people into their Ametnes workspace, grant them scoped access to projects, resources and locations, and remove that access again when someone leaves. It replaces shared logins with per-person memberships that can be reviewed and revoked individually.

The same model works at two very different scales:

  • Solo developers and small teams - invite your first collaborator on the free tier, with no upgrade and no separate access tooling.
  • Enterprises - run your organisation account on the same primitives: onboard members with scoped access instead of shared credentials, separate business units into their own workspaces, keep the owner accountable for every change, and offboard with a single revoke that is recorded in the audit log.

Concepts#

Term Meaning
Workspace An Ametnes account. Every user gets a personal workspace when they sign up.
Home workspace The workspace a user owns and was created with. The owner keeps root access to it.
Membership The link between a user and a workspace, including the access that link grants.
Owner The root user of a workspace. Only the owner can invite, update or remove members.
Member A user who has an active membership in someone else's workspace.
ACL An access-control entry attached to a membership. Grants are limited to projects, resources and locations.

A user can belong to several workspaces at once: their own home workspace plus any workspace they have been invited to. Access is always tied to the membership, not to a shared credential, so revoking a membership withdraws access immediately.

Membership states#

State Description
pending The invitation has been sent and is waiting for the recipient to accept or decline. Pending invitations expire after 7 days.
active The member has accepted and can switch into the workspace.
revoked The member left, or the owner removed them. Access is withdrawn.
expired A pending invitation that was not accepted within 7 days.

A revoked or expired membership can be re-issued later. The platform reuses the existing membership rather than creating a duplicate.

Before you start#

  • You must be signed in as the owner (root user) of the workspace to manage its members.
  • The workspace must be active.
  • Membership management is available on every plan, including the free tier.

Invite a member#

When you invite someone, the platform looks up the email address:

  • If a user with that email already exists, the invitation is attached to their account.
  • If no user exists, the platform creates one first, so the membership always resolves to a real person.

The invitee is added with the pending status and has 7 days to respond.

  1. In the console, open the workspace you own.
  2. Go to Users.
  3. Click Invite.
  4. Enter one or more email addresses.
  5. Click Send Invites.

The new member appears in the Users list straight away with a Pending status until they respond.

Review members#

The Users page lists everyone in the workspace with their name, email, the date they were added, their last login and their status. Use the status filter - All, Pending, Active or Inactive - to see who has joined and who has not responded yet.

Set or change what a member can access#

  1. In Users, open the member to view their profile.
  2. Open the Access Control Lists tab.
  3. Grant access to specific projects, resources and locations.
  4. Save your changes.

Note

Access is deny-by-default. A new member can see nothing until you grant it, and only projects, resources and locations can be granted - a membership cannot be used to widen access anywhere else.

Accept, decline or leave#

Invitations are accepted by the invited member, not the workspace owner.

  1. Open your own profile in the console.
  2. Open the Memberships tab, which lists the workspaces you belong to and any invitations still waiting.
  3. Click Accept to join or Decline to refuse an invitation.

To leave a workspace you have already joined, use the same Memberships tab and decline your membership.

Warning

You cannot leave your home workspace. The workspace you own always stays yours.

Switch between workspaces#

Once a membership is active, the workspace appears in your workspace list alongside your home workspace. Switching workspaces re-scopes the session to that workspace and to the access granted by the membership.

Remove a member#

  1. Open the workspace and go to Users.
  2. Find the member in the list.
  3. Choose Remove from workspace.

Their access is withdrawn immediately. Only the workspace owner can remove a member; a member cannot remove their own membership (use Decline on the Memberships tab to leave a workspace instead).

Access model#

  • Deny by default. A member of a workspace that is not their own is never treated as a root user. They can act only where the membership explicitly grants access.
  • Scoped grants. ACL entries can target projects, resources and locations only. This prevents a membership from being used to widen access sideways.
  • Owner-only administration. Inviting, updating and removing members is restricted to the workspace owner.
  • Audited. Invites, acceptances and departures are recorded in the audit log, so you can answer who was added, when, and by whom.

Troubleshooting#

Symptom What to check
The Invite button or member list is not available You may not be the owner (root user) of the workspace. Switch to the workspace you own.
An invitation stays Pending The recipient has not accepted yet. Pending invitations expire after 7 days; invite them again to re-issue it.
A user says they cannot see the workspace They have not accepted the invitation, or the invitation has expired.
A member joined but can see nothing Access is deny-by-default. Grant projects, resources or locations on the Access Control Lists tab.
A member cannot leave The home-workspace membership cannot be revoked.