Skip to content

Invite people and assign roles

People join a workspace through a verified-email invitation and receive explicit roles on each service. Workspace roles and service roles are assigned separately and never imply each other.

  1. Choose Invite member.
  2. Enter the person’s Email and pick an Initial workspace role: Member or Administrator. Owner is never offered.
  3. Choose Create invitation. The dialog becomes Workspace invitation ready and shows a one-time link. Copy it now; Helmhive stores only a hash and cannot show it again. An email is also queued, and its delivery state is shown next to the invitation.

Invitations expire after seven days by default. Pending ones can be revoked from Workspace invitations; accepted, revoked, and expired ones stay visible there. The email is sent by the installation your operator runs; if delivery shows Email failed, share the copied link directly. What the invitee sees is described in Accept an invitation.

  1. Choose Grant service access.
  2. Enter the Email, pick the Service, and pick the Role: Requester, Developer, or Administrator.
  3. Choose Grant access. An existing member is updated immediately. A new identity receives a verified-email invitation with the same one-time link handoff.

To replace a pending service invitation, submit the same email and role again. To edit an existing person’s roles, use the checkboxes on their card under People and roles and choose Save; adding or removing Developer or Administrator asks for confirmation, and removing the last role removes their access to that service.

Only the workspace Owner sees these controls. On a person’s card, Workspace role switches between Member and Administrator. Administrators manage membership, authentication, and repository sources; Members lose that authority but keep their service roles. Suspend removes access to the workspace and every service immediately while keeping history; Restore reverses it.

The people who operate Helmhive have no standing access to your workspace. To let a named operator help you:

  1. Choose Grant temporary access under Support access.
  2. Pick the Operator, a Scope (Read audit or Workspace administration), a Duration (1, 4, or 24 hours), and enter a Reason.

Grants expire on their own, can be revoked early, and remain visible after they end. An operator cannot create or extend a grant for themselves.