Skip to main content

Step-by-step guide

Set up team roles and workspace access

Invite organization members, choose their role and workspaces, manage seats, and keep team and client access separate.

Last updated
Updated September 17, 2026
Reading time
4 min read
For
Organization owner, Lab admin, Lab director
Access
Business and above

What you will accomplish

Invite an internal teammate with a suitable role, limit workspace and facility access, understand seat effects, and keep client or manufacturing access separate from internal membership.

Before you start

  • Open People & Access at /team and confirm the active organization.
  • Team membership requires Business or higher. Available seats and workspace limits come from the active plan; check /settings/billing and Pricing instead of relying on copied limits or prices.
  • Owner, Lab Admin, and Lab Director can manage team access when their effective permissions allow it. Only the Owner can manage billing.
  • Give each person only the role, workspaces, and facilities needed for their work.
  1. Choose the correct access population

Use internal organization membership for employees and trusted operators. Keep client users inside client-account and portal access. Keep manufacturing partner users inside their partner relationship. These populations appear together in /team for governance, but they are not interchangeable seats or roles.

  1. Choose an internal role

Select the role that matches the actual duty:

  • Owner controls the organization and billing.
  • Lab Admin and Lab Director manage broad lab operations and team access.
  • QA / Release can review technical evidence and approve release.
  • R&D Formulator can edit formulas and read technical records.
  • Production Lead and Production Operator execute batch work within their access.
  • Procurement / Inventory manages purchasing and inventory work.
  • Client / Program Manager coordinates relationship work.
  • Internal Reviewer and Auditor / Viewer are read-focused roles.

Custom roles may be available on Lab and above. A manager can invite only roles below their own hierarchy; Owner is not an invite option.

  1. Send a scoped invitation

Open /team/members/invite, enter the email address, and choose the role. Then choose their workspace access:

  • All workspaces for organization-wide workspace access.
  • Selected workspaces for only the checked records.
  • No workspace access when the person should join without workspace visibility.

Choose the same all, selected, or none pattern for facilities and optionally set a default facility. Add a message, send the secure invite, and use the backup invite link only when needed. The member remains pending until they accept.

  1. Review members, invitations, and seats

Use /team/members to review active members and pending invitations. A new active internal member consumes an organization seat. The billing owner can review seat capacity and supported adjustments at /settings/billing; current plan and seat terms belong to Pricing and the billing confirmation.

  1. Create and assign internal team workspaces

Use /team/workspaces to create internal team workspaces for operating areas such as R&D, quality, or production. A member's workspace access determines which operating areas they can see; their role determines what they can do there.

Your client accounts and programs are separate from internal team workspaces. Start and manage client work in Engagements, then use the Client Portal for client intake, files, review, and approvals. Client contacts and portal users are not internal employee seats.

  1. Audit and refine access

Review /team/audit and the security controls available to the plan. Remove old invitations, remove unneeded workspace or facility access, and change roles when duties change. Keep client records assigned to the correct client account and program.

Check your work

  • The invite belongs to the intended organization and email address.
  • The selected role matches the person's duties and authority.
  • Workspace and facility access show all, selected, or none exactly as intended.
  • The member count remains within the seat state shown in billing.
  • Client and manufacturing users were not added as internal teammates by mistake.
  • A test account can reach required records but not unrelated client work.

If something does not look right

  • If Invite is unavailable, confirm Business-or-higher access and member-management permission.
  • If a role is missing, it may be at or above your hierarchy; ask the Owner or a higher authorized manager.
  • If the invite exists but email delivery failed, copy the secure backup link from the result and share it through an approved channel.
  • If a user sees too much or too little, review both their role and their workspace or facility access.
  • If the seat limit blocks acceptance, ask the Owner to review seats in /settings/billing.

Next steps

Related next steps

Still need a person?

If Help and Docs did not get you where you need to go, send us your question and we'll route it to the right team.

Contact the Team
support@formuley.io