Invite and manage members
Add people to your organization, assign roles, and manage their access.
Before you invite someone
Use an active administrator account in the intended organization. Confirm the person’s name, email address, and required role. Creating a local person and giving an authenticated account organization access are separate steps; complete both parts of the workflow.
If your organization uses directory-managed membership, identify which system owns that membership before editing it in Durin. Keep the invited email aligned with the account the person will verify and use. Sending an invitation to one address does not authorize a different signed-in identity.
Invite a new member
Invite people to your Durin organization from the admin workspace.
- Switch to the Admin workspace.
- Go to People from the sidebar.
- Click Add user, enter their full name and email, choose Member or Auditor, and save.
- Open the person and choose Invite user to send an invitation.
- After they accept, sync and link their verified account. Adding a local person alone does not grant sign-in access.
Roles and permissions
Durin recognizes admin, security, member, and auditor roles. The current Admin workspace and administrative mutations require the admin role; security is not an administrator grant. Members and auditors can be invited directly. Auditors cannot execute tools. Personal views remain scoped to the signed-in account.
Revoke access
Open the linked account profile and use Revoke access when available. For directory-managed accounts, manage membership through the identity provider. Revocation is checked during authorization — active sessions for a revoked member fail closed on the next policy check.
Confirm the person can use the workspace
After invitation acceptance and verified account linking, have the person open Durin using that account. Start with the personal workspace and a connection intended for their team rather than using an administrator’s endpoint as a shortcut.
- Confirm the account is linked to the correct person and organization.
- Check that current membership is active and the role matches the intended access.
- Add the person to any locally managed teams needed for scoped connections, or wait for the authoritative directory update.
- Have the person complete their own provider authorization and a reviewed read, then check their activity record.
Resolve an invitation without creating duplicate people
If someone cannot sign in after receiving an invitation, check the accepted identity and verified account link first. A local People row alone is not sign-in authorization. Creating another local record with a similar name does not resolve an incorrect account link.
Ask which email the person actually used, then compare it with the invitation and verified account. If directory membership is authoritative, reconcile it at the identity provider. Keep role changes separate from troubleshooting the account link; granting administrator access is not a remedy for a failed invitation.
Verify revocation at the next access check
After revoking a supported linked account, confirm that a new request is denied. An existing client session or previously approved action cannot bypass current membership checks. For directory-managed users, verify the authoritative membership change has reached Durin before concluding that access was removed.