Skip to main content
Version: Latest

Your Team

Your PolicyArc account is an organization. Everyone you invite joins that organization and shares its environments. Team management lives on the dashboard's Settings page.

Every role can administer your policies

There is no read-only role today. Admin, Operator and Member all get full administrative access to every running environment's admin portal — including editing policy. The roles differ in who can create and destroy environments, and who can manage the team.

Invite people accordingly. If you need a genuine viewer role, tell us.


The three roles

AdminOperatorMember
See the organization's environmentsYesYesYes
Open an environment's admin portal — read and edit its policies, clients, connectors and resourcesYesYesYes
Create, start, stop and delete environmentsYesYesNo
Invite and remove members, change their rolesYesNoNo
Manage the organization and its subscriptionYesNoNo

Admin is the owner role. Give it to whoever should be able to add and remove people, and who is accountable for the subscription.

Operator runs the platform day to day — spinning environments up and down, and administering what is inside them. No control over the team.

Member is the narrowest role available, but it is not a viewer. A Member cannot create or destroy an environment, and cannot touch the team. Inside any environment that is already running, a Member has the same administrative reach as an Admin.

Why Member is not read-only

Opening an environment's admin portal proxies your request to that environment's Authorization Server using the environment's own root admin key. The AS admin API has no roles of its own, so the dashboard cannot hand out a narrowed version of it. Access to the portal is all-or-nothing, and every role has it.

That is why the permission to open a portal is separate from the permission to start and stop environments — the two are granted independently, and Member is the combination that has the first without the second.


Invite someone

You need the Admin role.

  1. Go to Settings in the dashboard.
  2. Click Invite member.
  3. Enter their work email address and pick a role.
  4. Send it.

The invitation appears under Pending invitations until they join.

What they receive

Two emails, back to back:

  1. The invitation — from PolicyArc, naming you, your organization, and what the role lets them do. It carries an Accept invitation button.
  2. A verify-email message — from the identity provider behind your login, once they start signing in.

Both are branded the same way on purpose. If someone reports getting only one, check your spam folder before anything else.

How they accept

The invitation is bound to the email address you typed, not to a secret link. They must sign in with that address. Signing in with a different one — a personal address, an alias — will not find the invitation.

There is nothing to copy or paste. Clicking the button takes them to the sign-in page; joining happens the moment they authenticate with the invited address.


Manage outstanding invitations

Invitations expire after 7 days. The date is printed in the email so the recipient knows, and the expiry is shown in Pending invitations.

To resend, invite the same address again. That issues a fresh invitation with a new 7-day deadline. If several are outstanding for one address, joining uses the newest and cancels the rest, so re-inviting is always safe.

To withdraw, click Withdraw on the row under Pending invitations.

Withdrawing is silent

Nobody tells the invitee. If they click their original button afterwards, they reach the sign-in page and then find no invitation waiting, with no explanation. Let them know yourself if it matters.


Remove someone

On Settings, use Remove member. Access ends immediately — including access to every environment admin portal.

Removing a member does not touch anything they created. Environments, policies and registered clients survive; they simply lose the ability to reach them.


Changing a role

An Admin can change any member's role from Settings. It takes effect on their next request — there is no need for them to sign out.

Promoting someone to Admin gives them the power to remove you. Demoting the last Admin would leave the organization with nobody who can manage it, so keep at least two.


Who gets told what

EmailGoes to
InvitationThe invited address
"Your PolicyArc account is ready"The organization's Admins only

The activation message is deliberately Admin-only: it ends in a Create your environment button, and that is a button an Operator or Member either cannot use or should not be the one to press first.