Agents you trust can now manage your team
Owners and admins can give an agent a key with the Manage the team permission, so it can invite people, change roles and remove members for them, within strict limits and with every change listed on the Team page.
Team administration used to need a person signed in to the dashboard. An owner or admin can now create an API key with the new Manage the team permission and hand it to an agent they run. With it, the agent can list the team, add and remove members, change roles, and send, list and revoke invitations in that workspace, acting for the person who created the key.
The key is held to limits a signed-in admin is not:
- It works only in its own workspace, and only while the person who created it is still an owner or admin there.
- It can never make anyone an owner or give a role above its creator's own.
- It never changes or removes the workspace owner or its own creator.
- Only a key an owner created can demote or remove an admin.
- The permission is granted by name only. A key with every permission, or with none set, does not carry it, and a token made from a key is refused.
An invitation a key sent can only be accepted while that key is still valid and its creator can still invite at that role; revoking the key cancels its pending invitations.
Only owners and admins are offered the permission, with a warning when they choose it. Every change a key makes, and every attempt it was refused, is recorded with the key and the person behind it. The Team page lists them so you can see what an agent did, and only owners and admins can read them.