# Manage members

Everyone in your workspace signs in with their existing work account — no new
passwords to manage. Admins manage people from **Settings → People**.

## Roles

Workspaces have two roles:

- **Member** — can publish and open projects.
- **Admin** — can also manage members, invites, and workspace settings.

Admins can change anyone's role from the People list. A workspace always
keeps at least one admin — the last admin can't step down until someone else
is promoted.

## Inviting people

From **Settings → People**, click **Invite people**. Enter one address or
paste a whole list (up to 20 at a time), choose the role they'll get, and
send. Invitees receive a link that adds them to the workspace when they sign
in.

Pending invitations appear in the **Invited** tab, where an admin can revoke
one at any time — a revoked link stops working immediately.

## Joining automatically

By default, workspaces are **invite only**. If you'd rather not invite every
teammate by hand, an admin can open joining to your whole company: in
**Settings → Security**, switch **Who can join** to **Anyone at your
domain**. From then on, anyone signing in with a verified email at your
company's domain joins automatically as a member.

Auto-join only ever applies to your own email domain — no one outside it can
join this way.

## External guests

Need to bring in a contractor, agency, or partner who doesn't have a company
email? Turn on **External guests** in **Settings → Security**. Admins can
then invite specific outside addresses; guests are clearly marked as
external and never join automatically — each one needs a personal invitation
from an admin.