Inviting members
Add the people on your team to GenAI Security Lab, and know exactly how each invite affects your seat count.

Seats first
Every active member on your team uses one seat. A seat opens up the moment someone joins, and it's released the moment they leave.
Team plans start at a 4-seat minimum. Check your seats used against your seat limit on the members page before you invite anyone — the invite form refuses to send once you're full. See the pricing page for current seat costs and how to add more.
Sending an invite doesn't hold a seatWe check you have room when you send it, but we don't reserve that seat for them. If your team fills up before they accept, the invite can't be redeemed until you free up or add a seat.
Send an invite
Enter an email address and a role, and we send a link to join your team. A brand-new address becomes a pending invite. Someone who already has an account on the platform — even on an Individual plan — can't be added this way; invites are only for people who aren't on GenAI Security Lab yet.
Bulk importAdding a lot of people at once? Upload a CSV with email and role columns to invite your whole roster in one pass.
An invite moves through three states:
| State | Meaning |
|---|---|
| Pending | Sent, not yet accepted. Valid for 14 days. |
| Accepted | They signed up and joined — now an active member, using a seat. |
| Expired | 14 days passed with no response. It can no longer be redeemed. |
Roles and permissions
Every member holds exactly one of four roles, set when you invite them and changeable later. Assign the narrowest role that lets someone do their job.

| Role | Can do |
|---|---|
| Team Admin | Runs the workspace — the only role that can change anything: invite and remove members, set roles, build groups and cohorts, push assignments, and manage licences and billing. The owner is always a Team Admin and can't be removed. |
| Team Member | Does the training. Runs labs, paths, and assignments and sees their own progress and the team roster — but no admin controls. |
| Read Only User | Read-only. Sees compliance evidence — coverage, reports, the audit log — and nothing else. Changes nothing and runs no labs. |
| Billing Admin | Owns the subscription — plans, seats, and spend. No access to members or the learning content. |
You can change someone's role later from their profile. What each role sees in coverage and reporting and the audit log follows directly from it.
Resend or revoke
Revoke a pending invite to withdraw it — useful if you typed the wrong address, or an invite has gone stale and you'd rather not leave it waiting to be accepted.
There's no separate resend button. Revoke the old invite, then send a new one to the same address; you can't have two pending invites for one email at the same time.
Revoking an invite doesn't change your seat count, because a pending invite never held a seat. To free a seat, remove an active member instead — that revokes their access immediately.
SSO-enforced teams
If your team restricts sign-in to specific email domains, that's enforced right at invite time: an address outside your allowed list is rejected before an email ever goes out.
Enterprise teams can go further and require single sign-on instead of a password. Once that's provisioned, an invited member authenticates through your identity provider rather than an emailed link, so it's worth setting your login policy before you send a wave of invites. Full detail lives on login policy.