Organizations, teams and projects
An organization is the top level: it holds the members, the seats, the billing plan and the organization-wide settings. A team groups projects and the people who work on them. A project is where your traces, evaluations, prompts, datasets and API keys live. Every member has one organization role. Below the organization, access comes from role bindings: a person on a team holds that role on every project in the team, and a project-level binding adds access on one project without removing the team role. A binding at the organization scope, which is what an organization Admin holds, applies to every team and project. Every member also gets a personal workspace on their first visit to the organization: one personal team with one personal project, listed under My Workspace and hidden from the team pickers. Also check: Access Control (RBAC) for what each role can do.Members
Settings > Members lists every member with their organization role and their access. Opening the page needsorganization:manage.
role on scope, with via <group> when the binding comes from a group.
Click a row to open the member dialog:
- Organization role: Admin, Member or Lite Member. You cannot change your own role.
- Access: the team and project bindings. Add a row with a role, a scope type (organization, team or project) and the team or project. Remove a row to revoke it.
- Group access: the bindings inherited from groups, read only.
Invite people
Click Add members. Enter one or more email addresses separated by commas, spaces or semicolons. Tick Lite Member to invite the whole batch on Lite seats. Under Team Assignments, add each team the person joins with the role on that team: Admin, Member, Viewer or a custom role. A Lite Member can only be assigned as Viewer. The drawer warns when a Lite Member invite has no team, because a Lite Member with no team sees no project. Click Send invites. When the deployment has no email provider, the button reads Create invites and you copy the invite link from the row menu instead. An invite link has the formhttps://app.langwatch.ai/invite/accept?inviteCode=... and works for 14 days. Resend invitation issues a new 14-day link, and Revoke cancels it.
Pending invites are listed under the members table with their status: Invited, Expired, Revoked, Accepted or Awaiting payment. An invite for a full seat over the plan limit opens the seat purchase dialog or the upgrade dialog before it is sent.
Let colleagues join by domain
The Who can join your organization section below the members table sets how people with a verified email address on your domain get in:Lite Members
A Lite Member is a read-only seat, counted apart from full seats. On a team or a project a Lite Member can read traces, analytics, evaluations, datasets, prompts, workflows, experiments and scenarios, and can create and update annotations. A Lite Member cannot see costs, the LangWatch AI Gateway pages or the audit log, cannot change anything else, and has the same limits over the API and MCP. In the settings pages a Lite Member can only hold the Viewer role.Teams
Settings > Teams & Projects shows every team with its projects and members. Click New team to create one; you are added as its Admin. The team card shows the members with their team role, which you can change in place, and an X to remove the member from the team. Members that come from a group are read only and showvia <group>.
Remove access
Deleting a member does not delete the traces, prompts or other work they created.