genai
SECURITY LAB
DocsFor teamsInviting members

Inviting members

Add the people on your team to GenAI Security Lab, and know exactly how each invite affects your seat count.

genaisecuritylab.com/team/users
Users and roles: invite members, track seat usage, and see what each role can do.
Users and roles: invite members, track seat usage, and see what each role can do.

Seats first

Every active member on your team uses one seat. A seat opens up the moment someone joins, and it's released the moment they leave.

Team plans start at a 4-seat minimum. Check your seats used against your seat limit on the members page before you invite anyone — the invite form refuses to send once you're full. See the pricing page for current seat costs and how to add more.

Sending an invite doesn't hold a seatWe check you have room when you send it, but we don't reserve that seat for them. If your team fills up before they accept, the invite can't be redeemed until you free up or add a seat.

Send an invite

Enter an email address and a role, and we send a link to join your team. A brand-new address becomes a pending invite. Someone who already has an account on the platform — even on an Individual plan — can't be added this way; invites are only for people who aren't on GenAI Security Lab yet.

Bulk importAdding a lot of people at once? Upload a CSV with email and role columns to invite your whole roster in one pass.

An invite moves through three states:

StateMeaning
PendingSent, not yet accepted. Valid for 14 days.
AcceptedThey signed up and joined — now an active member, using a seat.
Expired14 days passed with no response. It can no longer be redeemed.

Roles and permissions

Every member holds exactly one of four roles, set when you invite them and changeable later. Assign the narrowest role that lets someone do their job.

genaisecuritylab.com/team/roles
Roles and permissions: exactly what each of the four roles can reach.
Roles and permissions: exactly what each of the four roles can reach.
RoleCan do
Team AdminRuns the workspace — the only role that can change anything: invite and remove members, set roles, build groups and cohorts, push assignments, and manage licences and billing. The owner is always a Team Admin and can't be removed.
Team MemberDoes the training. Runs labs, paths, and assignments and sees their own progress and the team roster — but no admin controls.
Read Only UserRead-only. Sees compliance evidence — coverage, reports, the audit log — and nothing else. Changes nothing and runs no labs.
Billing AdminOwns the subscription — plans, seats, and spend. No access to members or the learning content.

You can change someone's role later from their profile. What each role sees in coverage and reporting and the audit log follows directly from it.

Resend or revoke

Revoke a pending invite to withdraw it — useful if you typed the wrong address, or an invite has gone stale and you'd rather not leave it waiting to be accepted.

There's no separate resend button. Revoke the old invite, then send a new one to the same address; you can't have two pending invites for one email at the same time.

Revoking an invite doesn't change your seat count, because a pending invite never held a seat. To free a seat, remove an active member instead — that revokes their access immediately.

SSO-enforced teams

If your team restricts sign-in to specific email domains, that's enforced right at invite time: an address outside your allowed list is rejected before an email ever goes out.

Enterprise teams can go further and require single sign-on instead of a password. Once that's provisioned, an invited member authenticates through your identity provider rather than an emailed link, so it's worth setting your login policy before you send a wave of invites. Full detail lives on login policy.

Was this page helpful?
Previous
Managing your plan