Team and roles
Every account belongs to one tenant — your organization. Members hold one of two roles:
| Role | Can do |
|---|---|
| Admin | everything, plus team management: invite teammates, promote / demote roles, remove members |
| User | full product access; the Team screen is read-only (sees the roster, cannot change it) |
The first person from an organization to enter Umbra becomes its admin automatically; everyone who joins later starts as a user. See Sign in and activation.
Inviting a teammate
Admin-only, from the Team screen:
- Enter the person's email and name, pick a role, and Send invite.
- They receive an email with a temporary password for their new Wazuh ID account.
- On first sign-in they choose a real password and land directly in your organization — an invitee never starts a separate tenant.
A pending invitee shows as Pending invite in the roster until they finish that first sign-in, then flips to Active.
Invites are a plan entitlement: 1 seat on Free, 5 seats on Pro. See Plans and billing.
Enforcement
Roles are enforced server-side: the API only lets an admin invite, change roles, or remove members — regardless of what any client shows. Tenant isolation is likewise enforced in the backend, so members of one organization can never see another organization's data.