Team members
Manage who belongs to your workspace under Settings → Members. Roles and what each person can do are governed by groups and capabilities — see Permissions & groups. This page covers the day-to-day membership actions.
Invite a member
Section titled “Invite a member”With the Invite Members capability, open Settings → Members and send an invitation:
- Enter the person’s email address and pick a starting role (Member or Viewer — promote to admin later via groups).
- Orimora emails them a single-use invitation link that expires after 7 days.
- They accept, set up sign-in (magic link, passkey, or SSO), and join the workspace.
Pending invitations are listed under the invite form, where you can resend (issues a fresh link) or revoke one.
Roles at a glance
Section titled “Roles at a glance”The members list shows each person’s role, their groups, and badges:
- Owner — the protected workspace owner (one per workspace). Cannot be suspended, demoted, or removed; see Workspace owner.
- You — your own row.
- Role label (Admin / Member / Viewer) derived from system-group membership.
Change a member’s role from the dropdown on their row (requires the appropriate group-management capability). You don’t create an admin directly — you invite a member and then promote them; promoting to Admin asks for confirmation, since it grants full workspace access. You cannot change your own role or the owner’s role here.
Suspend or reactivate
Section titled “Suspend or reactivate”With the Suspend Members capability you can suspend a member — they are signed out immediately (every session and credential is revoked) and cannot sign back in until reactivated. Reactivating restores access; their content and group memberships are untouched.
Suspension is refused in three cases, to avoid locking the workspace out:
- You cannot suspend yourself.
- You cannot suspend the last administrator.
- You cannot suspend the workspace owner (transfer ownership first).
Recover a member’s email
Section titled “Recover a member’s email”Orimora changes an email address only after dual confirmation from both the old and the new mailbox. If a member’s old mailbox is permanently inaccessible, they can no longer self-serve — so a system administrator can set their address directly:
- Settings → Members → the member’s row → Recover email.
- Enter the new address and confirm. This is step-up protected.
- The change applies immediately (bypassing dual confirmation); the previous address is notified and the action is recorded in the audit log.
See also
Section titled “See also”- Permissions & groups — roles, capabilities, and the workspace owner
- Single sign-on (SSO) — SCIM auto-provisioning and deprovisioning
- Security — sign-in, MFA, account controls