Skip to main content

Team and roles

Every account belongs to one tenant — your organization. Members hold one of two roles:

RoleCan do
Admineverything, plus team management: invite teammates, promote / demote roles, remove members
Userfull product access; the Team screen is read-only (sees the roster, cannot change it)

The first person from an organization to enter Umbra becomes its admin automatically; everyone who joins later starts as a user. See Sign in and activation.

Inviting a teammate

Admin-only, from the Team screen:

  1. Enter the person's email and name, pick a role, and Send invite.
  2. They receive an email with a temporary password for their new Wazuh ID account.
  3. On first sign-in they choose a real password and land directly in your organization — an invitee never starts a separate tenant.

A pending invitee shows as Pending invite in the roster until they finish that first sign-in, then flips to Active.

Invites are a plan entitlement: 1 seat on Free, 5 seats on Pro. See Plans and billing.

Enforcement

Roles are enforced server-side: the API only lets an admin invite, change roles, or remove members — regardless of what any client shows. Tenant isolation is likewise enforced in the backend, so members of one organization can never see another organization's data.