How to Invite Team Members and Assign Roles

Beginner 10 minutes Org Admins / Owners Team & Access Management

Invite users via email, understand the role hierarchy (member, manager, admin, owner), and configure what each role can access.

Overview

Chainsaw uses role-based access control (RBAC) to determine what each user can see and do. This tutorial covers inviting team members, understanding the role hierarchy, and managing user access.

Prerequisites

  • Admin or Owner role in Chainsaw
  • Team members’ email addresses

Step 1: Understand the Role Hierarchy

Chainsaw has four organization-level roles (plus a global admin role):

RoleLevelCapabilities
Global Admin4Full system access. Can manage all organizations. Only assignable at the system level.
Owner3Full organization access. Can manage settings, users, policies, BOM, and audit. Can invite users and assign roles.
Admin3Same as Owner within the organization. Can manage settings and users.
Manager2Can access Policies, BOM, and Audit. Can view and manage most operational features but cannot change org settings.
Member1Read-only access to Overview and Repositories. Cannot access policies, BOM, audit, or settings.
Role hierarchy diagram
The role hierarchy from Member (most restricted) to Global Admin (full access)

What Each Role Can Access

FeatureMemberManagerAdmin/OwnerGlobal Admin
Overview DashboardYesYesYesYes
TrafficYesYesYesYes
RepositoriesYesYesYesYes
PoliciesNoYesYesYes
Bill of MaterialsNoYesYesYes
Audit ReportsNoYesYesYes
Billy (AI Assistant)YesYesYesYes
Access (Credentials)YesYesYesYes
Members ManagementNoNoYesYes
SettingsNoNoYesYes
Global Admin PanelNoNoNoYes

Step 2: Invite a Team Member

Navigate to Access and switch to the Members tab.

  1. Click Invite Member
  2. Enter the team member’s email address
  3. Select their role
  4. Click Send Invitation
Invite member form
Enter the email and select a role for the new team member

The invited user receives an email with a link to accept the invitation.

Assign the minimum role needed. Most developers only need Member access. Security team members typically need Manager. Reserve Admin/Owner for those who manage the organization.

Step 3: Accepting an Invitation

When a team member clicks the invitation link, they’re taken to the invitation acceptance page:

New Users

  1. View the invitation details (role, organization, expiration)
  2. Create an account with their email and a password
  3. Click Accept Invitation
New user accepting an invitation
New users create an account as part of accepting the invitation

Existing Users

If the user already has a Chainsaw account:

  1. Log in if not already authenticated
  2. View the invitation details
  3. Click Accept
Existing user accepting an invitation
Existing users simply confirm to join the organization
Invitations expire after a set period. If an invitation expires, you’ll need to send a new one.

Step 4: Manage User Roles

After a user joins, you can change their role:

  1. Navigate to Access → Members
  2. Find the user in the list
  3. Click on their role to change it
  4. Select the new role from the dropdown
Changing a user's role
Update a user's role from the Members list

Step 5: Manage Groups

Groups let you organize users for policy targeting. You can create policies that apply to specific groups of users.

  1. Navigate to Access → Members
  2. Create a group (e.g., frontend-team, security-team)
  3. Add users to the group
Managing user groups
Organize users into groups for policy scoping

Groups can then be referenced in policy scope to apply rules to specific teams.

Step 6: Reset User Passwords and 2FA

As an Admin or Owner, you can help team members with account issues:

Reset Password

  1. Find the user in the Members list
  2. Click Reset Password
  3. The user receives a password reset email

Reset 2FA

If a team member loses access to their authenticator app:

  1. Find the user in the Members list
  2. Click Reset 2FA
  3. The user can set up 2FA again on next login
Password and 2FA reset options
Admins can reset passwords and 2FA for team members

Best Practices

  • Start with Member role — Promote users to higher roles as needed
  • Use groups — Organize by team for easier policy management
  • Enable 2FA — Encourage all users to set up two-factor authentication
  • Review access periodically — Remove users who no longer need access
  • Separate service credentials — Use client credentials (not user accounts) for CI/CD pipelines

Guided Tours for New Members

Chainsaw includes interactive guided tours that help new team members learn the interface. Tours start automatically on first login and can be replayed from the navigation bar.

Guided tour for new users
New team members get an interactive tour of the dashboard

Next Steps