/users) is where you invite teammates to your account and manage everyone who already has access. Every invited teammate is a shared user — a separate login tied to a role that controls what they can see and do, distinct from your own account (the Owner).
Inviting a user
Open the Invite Users drawer
Enter the teammate's name and email
Choose a role

The Invite Users drawer filled in with a name, email, and the default Viewer role's live permission preview
Turn on Tag-based Permission (optional)
Send the invite
The Users table
Every teammate you’ve invited shows up in a table with these columns:
A pending invite in the Users table, with the row selected to reveal the bulk-actions toolbar
Bulk actions
Select one or more rows with their checkboxes to reveal a floating toolbar with three bulk actions:-
Change Role — opens a small dialog to assign a new role to every selected user at once.

The bulk Change Role dialog for one selected user
- Deactivate — only affects users with Active status; pending invitations are excluded from a bulk deactivate even if their row is selected.
-
Remove — permanently removes the selected shared user(s) from your account, after a confirmation.

The confirmation popover for removing a single user
Per-user tag permissions
On accounts with the tag-based permissions feature enabled, each row gets an additional edit control for that user’s tag scope — the same Assign Tags and include untagged options available at invite time, editable after the fact. As with the invite-time toggle, this control didn’t appear on the Pro-plan test account used to verify this page (itsTag Permissions column in the CSV export, described below, showed - for every row).
Exporting the list
Click Export in the page header to download a CSV of every shared user on the account — including the account Owner — with columns for role, invite/acceptance timestamps, status, tag permissions, MFA status, QR codes created, and last login.Related
- Roles & permissions — what each default role grants, and how custom roles work.
- Single Sign-On — on SSO-login accounts, the MFA column above is hidden entirely since the identity provider handles authentication.