Skip to main content
Everyone who works in your account is managed from one page: open Users in the sidebar — depending on your account it sits at the top level or under More. Only root and admin can invite, change a role, suspend or remove someone. Developer and monitor can open the page and read the list, but cannot change anything on it. Billing and collaborator do not see it at all.

Seats

A seat is one non-suspended person on the account.

Free

2 seats. To add a third person, move to a paid plan.

Pro and Team

Unlimited seats. The plan is a flat monthly price — adding people does not change it.
Two things do not consume a seat:
  • Suspended users. Suspending someone frees their seat immediately. You do not have to delete them to get it back.
  • Clients. A user with the client role never consumes a seat, on any plan.
QuivaWorks does not charge per user. Pro and Team are flat monthly subscriptions, and what you are billed for is usage — credits, storage and meeting hours. Plans and pricing →
When the account is at its seat limit, the Users page shows an Update Plan button and the Invite button is disabled with the limit in its tooltip. Un-suspending someone is checked against the same limit, so while you are full an un-suspend is refused until a seat is free.

Inviting someone

1

Open Users

Open Users in the sidebar.
2

Click Invite

The Invite button is in the top right. It only appears for root and admin.
3

Fill in the invitation

  • Email — where the invitation goes
  • Role — one of admin, developer, monitor, billing, collaborator or client
  • First Name and Last Name
What each role can reach →
4

Send

Click Invite.
The person appears in the list with the status Invitation Pending until they accept. User Invitation Email Clients are invited the same way but get a passwordless invitation: a magic link and a 6-digit code, either of which signs them in through Passwordless Client Sign-In on the login page.
There is no “resend invitation” control. If an invitation does not arrive, check the recipient’s spam folder and confirm the address on the list is right.

The Users page

The list is titled Manage Users and has five columns: Name, Email, Role, Status and Last Login. Status is one of Active, Suspended or Invitation Pending. Above the table are a search box and two filters, Role and Status, so you can pull out (for example) everyone suspended, or everyone holding admin. Click a person’s name to open them. Their card carries the Role dropdown with Update Role, and a dot menu with everything else.

Roles

Root

The account creator. Cannot be assigned to anyone.

Admin

Full management except closing the account.

Developer

Secrets, Monitor and Flows. Reads the member list.

Monitor

Monitor, and reads the member list.

Billing

Billing & Plans. No Users, no Account.

Collaborator

No Flows, Users, Secrets or Gateway.

Client

External, passwordless, scoped by grant. No seat.

Changing a role

Open the person, pick a role from the Role dropdown and click Update Role.
Changing a role signs that person out of the account. They sign in again and come back with the new access.
A root user’s row shows their role as fixed text with no dropdown and no dot menu, so root users cannot be re-roled, suspended or deleted from this page.

Scoping a client to specific resources

For a user with the client role, root and admin see an extra dot-menu item: Manage Resources. It grants access to named Spaces, flows, assistants, records, record configurations, files, folders and tasks, with Read, Write and Delete on each — plus Execute where the type supports it. A client with no grants sees nothing. More on the client role →

Suspending users

Suspend blocks someone from signing in, without deleting anything they own.
1

Open the person

Click their name on the Users page.
2

Suspend

Dot menu (⋮) → Suspend.
Their status becomes Suspended and their seat is freed. To reverse it, use Unsuspend in the same menu — it is checked against your seat limit, so it will be refused if the account is full.
Suspending someone does not end the sessions they already have. If you need them out immediately, use Logout as well.

Logging a user out

Logout in the dot menu revokes that person’s tokens and ends their sessions everywhere. Use it when a device is lost, when you suspect unauthorised access, or alongside a suspension.

Deleting users

1

Open the person

Click their name on the Users page.
2

Delete

Dot menu (⋮) → Delete, then confirm.
Deletion cannot be undone. Resources created in the account stay in the account; the person’s access to it is removed.
To bring someone back, send a fresh invitation to the same address.

Recovery codes

Root and admin can view or reissue another person’s recovery codes from their dot menu. Both entries are hidden while an invitation is still pending.
  • View recovery codes — shows the codes currently in force.
  • Issue new recovery codes — confirms first, warning that the user’s old codes will no longer be valid, then shows the new set.
Whenever recovery codes are viewed, the user is emailed a “security codes viewed” notice, so nobody’s codes can be read without them knowing.
There is no admin-initiated password reset. Someone who cannot get in uses Forgot Password on the login page themselves.

Onboarding and offboarding

  1. Pick the narrowest role that lets them do the job — collaborator or client is often enough for someone outside the core team.
  2. Invite them, and check the invitation arrived.
  3. For a client, set their resource grants with Manage Resources before you tell them to sign in. Until you do, they will see an empty dashboard.
  4. Encourage them to set up two-factor authentication and store their recovery codes.
  1. Logout — ends their existing sessions straight away. Suspension alone does not.
  2. Suspend — blocks any new sign-in and frees the seat.
  3. Check whether anything they owned needs handing over.
  4. Delete when you are sure, or leave them suspended — a suspended user costs you nothing.
The Last Login column and the Role filter are the two tools for this. Look for people who have not signed in for a long time, and for elevated roles that outlasted the reason they were granted.Remember that developer and monitor can both read the whole member list, so “they only have monitor” is not the same as “they cannot see who works here”.

Troubleshooting

Your account is at its seat limit — the tooltip shows the limit, and an Update Plan button appears next to it. Free accounts have 2 seats. Suspending someone frees a seat, and inviting a client does not use one at all.
Un-suspending takes a seat back, so it is checked against the same limit as an invitation. Free up a seat or move to a paid plan first.
Suspension blocks new sign-ins; it does not end sessions that already exist. Use Logout in their dot menu.
Only root and admin can. Root itself cannot be assigned or changed by anybody — a root row has no role dropdown.
Billing and collaborator do not get the Users item, and clients see only their own dashboard. Everyone else does — but developer and monitor get read-only access.

Roles & Permissions

What each of the seven roles can reach

Client Portal

What a client user actually sees

Plans & Pricing

Seats, credits and what is actually billed

Authentication

Passkeys, two-factor and recovery codes

Sessions

Active logins and how to end them

Security Overview

Protecting your account