Dokki Docs logo

Org Members & Roles

Organization roles control organization-wide administration. Workspace roles separately control what a person can do inside each workspace.

Organization roles

  • Owner — manages the organization and its highest-level settings.

  • Admin — helps manage members and organization settings.

  • Member — participates in the organization and can be added to workspaces.

Workspace access is separate

Joining an organization does not automatically open all of its workspaces. Add the person to the specific workspace and choose the appropriate workspace role. A resource can have additional sharing settings that narrow or extend access.

Add someone to a workspace

  • Open the workspace member settings.

  • Search for an existing member of the organization.

  • Select the person and choose the workspace role.

  • Review the result before closing the settings.

If the person is not yet in the organization, add or invite them through organization member management first.

Change a role

Use the smallest role that still allows the person to do their job. Before removing an admin or owner, make sure another person can continue managing the organization or workspace.

Offboard a member

Open organization member management and choose the member's offboarding action. Dokki first shows the affected workspaces, resources, permissions, agents, schedules, active runs, work items, integrations, and credentials.

Choose an active member as the successor, decide whether to copy the departing member's direct workspace and document permissions, and complete the confirmation. Organization roles are never copied.

Confirming immediately freezes the member's organization access and releases their assigned license. Dokki then transfers supported ownership in the background. The transfer is retryable if part of it fails.

Credentials are revoked rather than transferred. This includes API keys, sessions, SSO and MCP grants, and external connections. Historical authorship remains attributed to the original person.

Reactivate an offboarded member

Reactivation requires an available license. It restores organization access, but it does not reverse the completed transfer: assets and permissions do not automatically move back, revoked credentials remain revoked, and paused automations may need to be configured again.

Troubleshooting access

If someone can see the organization but not a workspace, check workspace membership. If they can open the workspace but not one resource, check that resource's sharing settings.

Org Members & Roles | Dokki Docs