Team and roles
Every account belongs to one tenant, your organization. Members hold one of two roles:
| Role | Can do |
|---|---|
| Admin | everything, plus team management: invite teammates, promote or demote roles, remove members |
| User | full product access. The Team screen is read-only, showing the roster without allowing changes |
The first person from an organization to enter Umbra becomes its admin automatically. Everyone who joins later starts as a user. See Sign in and start your workspace.
Inviting a teammate
Admin-only, from the Team screen:
- Enter the person's email and name, pick a role, and Send invite.
- They receive an email with a temporary password for their new Wazuh ID account.
- On first sign-in they choose a real password and land directly in your organization. An invitee never starts a separate tenant.
A pending invitee shows as Pending invite in the roster until they finish that first sign-in, then flips to Active.
Enforcement
Roles are enforced server-side: the API only lets an admin invite, change roles, or remove members, regardless of what any client shows. Tenant isolation is likewise enforced in the backend, so members of one organization can never see another organization's data.