Account

Inviting Team Members and Setting Roles

Your Kapsule account can be shared with colleagues, contractors, and accountants by sending each of them an email invitation and giving them a role that decides exactly what they can see and change.

Everything to do with people lives on one page: Settings, then Team in the Workspace group of the settings rail. It lists everyone who currently has access, any invitations still waiting to be accepted, and the invite form itself.

Who Can Manage the Team

Only the Owner and Admin roles can invite, change a role, or remove someone. If you sign in with any other role, the Team page still shows you the member list and the role legend, but the invite form and the per-row controls are hidden.

Two further guardrails apply even to an Owner or Admin:

  • You cannot change or remove your own membership from this page.
  • You cannot change or remove the Owner. There is exactly one Owner per account, and only the Owner can transfer ownership or delete the account.

The Five Roles

The role legend at the bottom of the Team page is the authoritative description, and it is reproduced here.

RoleWhat it can do
OwnerFull account access. Can transfer ownership, delete the account, and do everything an Admin can. Only one Owner per account.
AdminFull management except transferring ownership. Invites and removes teammates, changes settings, billing, and provisions services.
BillingBilling only. Manages payment methods, subscriptions, and invoices. Can view sites and services but cannot change them or the team.
SupportRead access plus ability to respond to support tickets on your behalf. Cannot change billing, settings, or team.
ViewerRead-only access to dashboards, sites, mailboxes, and settings. Cannot make any changes.

Give an external developer Admin only if they genuinely need to provision and delete services. If they are building a site you already created, Viewer plus SFTP or SSH credentials for that one site is usually enough, and it keeps your billing and domain records out of reach.

Sending an Invitation

Team page in KPanel settings showing members, roles and the invite form

  1. Go to Settings, then Team.
  2. Scroll to the Invite a teammate card.
  3. Enter the person's email address in the address field.
  4. Pick a role from the dropdown. The four selectable options are Admin: full access, Billing: payments and plans, Support: read and tickets, and Viewer: read-only. Owner is not offered here because it is transferred, not granted.
  5. Read the blue explanation panel underneath. It updates as you change the dropdown and spells out what that role can do.
  6. Click Send invite.

You will see the confirmation "Invite sent to" followed by the address, and the invitation appears in the Pending invites card.

Pending Invites and How They Expire

The Pending invites card only appears when at least one invitation is outstanding. Each row shows the invited address, the role in a coloured pill, when it was sent, and how long the invitation has left, counted down in days.

Invitations are single-use links delivered by email. If one is not accepted before it expires, send a new one from the same form.

To withdraw an invitation, click the small cross at the end of its row. The panel asks you to confirm, warning that "The invite link for that address will stop working. They won't be notified." Nothing is emailed to the invitee when you revoke.

An invitation is tied to the email address you typed. If your colleague signs up with a different address, the invitation stays pending and unused. Ask them which address they used and re-invite that one.

Changing Someone's Role

On the Team page, find the person in the Team members list. Where you have permission to change them, the role pill is replaced by a dropdown. Choose the new role and it saves immediately, confirmed by a "Role updated" message. There is no separate save button.

Role changes take effect on the member's next page load. If you are downgrading someone during a security incident, remove them instead so their access ends immediately, then re-invite them once things are calm.

Removing a Team Member

Click the red bin icon at the end of the member's row. A confirmation dialog appears and states plainly that the person "will lose access to this account immediately. You can re-invite them later."

Removal takes their access away from every part of the account at once: the panel, billing, sites, mailboxes and domains. It does not delete anything they created. Sites, mailboxes and domains belong to the account, not to the member who set them up.

Removing a teammate does not revoke API keys they created, because API keys belong to the account rather than to a person. If someone leaves, review Settings, then Security, and revoke any key they made. See API Keys and Developer Access.

What Each Member Sees About Themselves

Each row shows the display name (or email address when no name is set), the email address, and how recently they signed in, shown as "last active today", "yesterday", a number of days, or a number of months. Your own row carries a You badge, and the Owner's row carries a crown icon.

That last-active column is a useful housekeeping tool. A contractor who has not signed in for months is an account worth removing.

Keeping the Team Honest

Two habits keep a shared account safe:

  • Review the list quarterly. People change jobs and agencies finish projects. The Team page is the only place that access is granted, so it is also the only place it needs to be checked.
  • Watch the audit log. Every action taken in the account is attributed to the person who took it. See Reading Your Account Audit Log for how to filter it by person, resource, or IP address.

If you suspect a teammate's own login has been taken over rather than misused, treat it as a compromise: remove them, then follow Account Security and What to Do If Your Site Is Hacked.

Troubleshooting

The invite form is not showing. You are signed in with a role below Admin. Ask the Owner or an Admin to send the invitation.

"That email is already in use." The address already belongs to a Kapsule login. It can still join your account, but ask the person to accept the invitation while signed in to that existing login rather than creating a second one.

The invitation email never arrived. Ask them to check spam and promotions folders. Invitations are sent from our transactional mail platform, so a strict corporate filter can quarantine them. Revoke the pending invite and send a fresh one to a personal address if their work filter keeps blocking it.

A member says they cannot see billing. That is correct for the Support and Viewer roles. Only Owner, Admin, and Billing reach the Billing pages. See Understanding Your Billing Page.

Still need help?

Email us at support@kapsulehost.com or open a chat in KPanel.

Open KPanel
Inviting Team Members and Setting Roles