Guides

Users, Roles & Groups

Invite your team, assign the admin role, organise members into groups, and manage seats.

Everything to do with your team lives under Settings → Users & Groups, which only organization admins can see.

Roles

Airlock has two roles.

RoleWhat it can do
USERUse the integrations, skills, and agents they've been given access to; connect their own credentials; approve requests they've been assigned; manage their own account and personal API tokens
ADMINEverything a member can, plus every administrative surface

Admin unlocks, specifically: creating and configuring integrations, editing tool policies, service accounts, the Security settings (allowed AI clients, network access, anomaly detection, skill security), the AI use policy, directory sync, organization settings, the instruction library, organization-owned skills, and access grants. Admins also bypass access scoping entirely.

Promote or demote a member from Settings → Users & Groups. Note that directory sync never assigns the admin role — every synced user arrives as a regular member, so admins are always promoted by hand.

Membership states

A person you'll see on the Users tab is in one of these states:

StateMeaningWhat to do
InvitedYou sent them an invitation; they haven't signed in yetResend or cancel the invitation
PendingThey signed up themselves against your organization's email domain and are waiting for youApprove or reject them
ActiveA full member
DeactivatedSet only by directory sync, when your identity provider deactivates the user; their sign-in no longer worksRe-activate them in your identity provider — airlock has no reactivate action

Pending is the one that catches people out. When someone signs up with a corporate email domain that already has an airlock organization, they join your organization as a pending member rather than founding their own — and they see a "waiting for approval" screen until an admin approves them. Personal email domains always get their own isolated organization.

Inviting your team

  1. Open Settings → Users & Groups.
  2. Under Invite Users, enter the person's email address and send the invitation.
  3. They appear under Pending Invitations until they sign in. From there you can resend the invitation or cancel it.

Seats

Your organization has a seat limit. You can see it on Settings → Organization as N / M seats used, and the Add User button is disabled once you reach it, with the message "Seat limit reached (N/M)."

Invited and pending members count against the limit, not just active ones — an unaccepted invitation holds a seat until you cancel it. If you're at the limit and expecting someone to join, cancel a stale invitation first.

Like the plan flag, seats are set by airlock rather than bought in-app. Contact us to raise the number. See Billing & Usage for the other limits.

Groups

Groups are how you manage people at scale instead of one at a time.

  1. Open Settings → Users & Groups.
  2. Under Groups, click Create Group.
  3. Add members.

A group is used in three places:

  • Approvals — assign a group as the approver for a tool, and any member of it can approve. See Approval Workflows.
  • Access grants — scope an integration, skill, or agent to a group. See Access Control.
  • Allowed AI clients — restrict a given AI client to specific groups under Settings → Security. See Security.

Prefer groups over individuals in both. Onboarding someone then becomes a single membership change rather than a sweep across every resource and every tool.

If you use directory sync, your identity provider's groups are synced into airlock and their membership is kept in step, so access follows your directory automatically.

Offboarding

  • Remove the user in airlock — the trash icon on their row on the Users tab. This is permanent and cannot be undone. If you use directory sync, offboard them in your identity provider instead, which marks them Deactivated rather than deleting them. Either way their sign-in stops working and their live sessions are revoked.
  • Revoke their personal API tokens if they had any. An admin can see and revoke every personal token in the organization from Settings → Security.
  • Reassign their approvals. If they were the only approver on a tool, add someone else or those requests will sit pending.

Because removal is irreversible, prefer directory-sync deactivation when you have it — a returning colleague is then re-enabled in your identity provider rather than re-invited from scratch.