Members and roles
Invite people to your workspace, choose what each person can do, change a role, remove someone, or hand the workspace to another owner.
Everyone in a workspace has one role. The role decides what they can open, what they can change and whether they get the console at all. Nobody is priced per seat, so adding people never changes your bill.
Roles
| Role | Who it suits | In short |
|---|---|---|
| owner | The person who created the workspace, or who was handed it | Everything, including closing or deleting the workspace |
| admin | People who run the workspace day to day | Everything except the owner-only decisions below |
| read-only | People who need answers but should change nothing | Opens every page and asks questions. Changes nothing |
| reader | People who only read reports | Reads the reports you publish to the reports portal. No console |
When you invite someone you choose Admin, Read-only or Reader · reports portal only. Owner is not offered on the invitation. Ownership moves by handing the workspace over.
The account block at the foot of the left rail shows the signed-in person's role in the same words as the invitation, for example Read-only.
What each role can do
| owner | admin | read-only | reader | |
|---|---|---|---|---|
| Open every console page and see who is in the workspace | Yes | Yes | Yes | No |
| Ask cherry, run questions and search | Yes | Yes | Yes | Portal only |
| Open the reports portal and read the reports published to you | Yes | Yes | Yes | Yes |
| Change things: connections, the semantic fluid, modelling, reports, schedules | Yes | Yes | No | No |
| Provision or delete a warehouse, change warehouse limits, use the SQL shell | Yes | Yes | No | No |
| Define, rebuild or remove a sanda search service | Yes | Yes | No | No |
| Create integration tokens, and approve or decline what an agent asks to do | Yes | Yes | No | No |
| Change the workspace name, report colours and report delivery domains | Yes | Yes | No | No |
| Change the monthly budget or daily AI limit, resume a suspended warehouse, move between Basic and Standard or ask for another edition | Yes | Yes | No | No |
| Change how cherry works | Yes | Yes | No | No |
| Invite people, change roles, remove people other than an owner | Yes | Yes | No | No |
| Switch sanda search on or off for the workspace | Yes | No | No | No |
| Require two-step sign-in for everyone | Yes | No | No | No |
| Hand the workspace to an admin | Yes | No | No | No |
| Close, reopen or delete the workspace | Yes | No | No | No |
| Set up two-step sign-in, sign out other sessions, accept the privacy policy, send a support message | Yes | Yes | Yes | Yes |
Two things are worth knowing about the reader and read-only rows.
- A read-only person asks questions through cherry, the results pane, search and MCP, and cannot commit changes through any of them. They can still disconnect an app they connected themselves.
- A reader has no console. When they sign in they go straight to the reports portal, where they can ask cherry about the reports published to them unless you switch that off. Any data rules you set for them apply to everything they ask.
An admin can do almost everything, but some decisions stay with the owner: closing, reopening, deleting or handing over the workspace, changing or removing another owner, switching sanda search on or off (it decides whether your text may leave Australia), and requiring two-step sign-in. The Role hint on the invitation lists the same things when you choose Admin. See Privacy and your data.
Invite someone
- Open the Team panel. Go to Settings · Team and press Invite someone.
- Fill in the invitation. Enter their Work email. Name is optional, and they confirm it when they join. Choose a Role. The hint under the field says what that role means.
- Send it. Press Send invitation. sanda confirms with "Invitation sent to" their address. The link works once and expires in 7 days.

The invitation appears under Invited, not yet joined, with the days left. From there you can:
- Resend to send a fresh link. The old link stops working and the 7 days start again.
- Revoke to withdraw it. The link stops working at once.
If the email could not be delivered, sanda tells you, and you can press Resend again in a moment.
What the person sees
The link opens a page headed "Join Acme Services on sanda." (with your workspace name). It says who invited them and as which role, and shows their email address, which they cannot change. They enter Your name and press the button named for the workspace, for example Join Acme Services. That signs them in. Readers land in the reports portal. Everyone else lands in the console.
The first time they open the console they read and accept sanda's privacy policy, as every person does. See Privacy and your data. Next time they sign in with their email address and a one-time link. See Sign in.
Rules that always apply
- One address belongs to one workspace. If the address already belongs to another sanda workspace, the person is told to ask for an invitation to a different address.
- You cannot invite an address that is already in your workspace, or your own.
- A link works once. After it is used, withdrawn or expired, the page says which, and the person asks you for a new one.
- A workspace that has been closed does not take new members.
Change a role
Use the role menu on the person's row in Settings · Team and pick Admin, Read-only or Reader · reports portal only. The change applies from their next request.
If you move someone out of admin, sanda also withdraws any invitations they sent that nobody has accepted yet. Integration tokens and connected apps they made keep working, but they lose the permissions only an owner or admin can hold, such as running or committing SQL.
Remove someone
Press the bin icon on their row, then Yes, remove. Removing someone:
- ends their membership and signs them out of this workspace immediately;
- withdraws invitations they sent that were not yet accepted;
- stops any integration token or connected app they made from opening anything;
- keeps what they built. Connections, reports and the record of what they did stay in the workspace.
They can be invited again later, or to another workspace.
Nobody can change their own role or remove themselves. An admin cannot change or remove an owner. The owner cannot be removed at all while they are the only owner. To step down, hand the workspace over first.
Hand the workspace to an admin
Only the owner can do this, and only to an admin. If the person you want is not an admin yet, change their role first.
- Find the admin's row. In Settings · Team, press Make owner on their row.
- Confirm. sanda asks, "Hand this workspace to" that person, and tells you that they become the owner and you become an admin. Press Yes, make them owner. Press Keep it to cancel.
It is a swap in one step. Both of you get an email saying so. Only the new owner can undo it.
Something unclear or out of date? Tell us, and we will fix the page.