Team
Terminology
The Manage Team feature is the central administrative hub in SpendCraft, serving as the governance layer for user access and application‑wide permissions. It defines who is authorized to use the platform and establishes their foundational capabilities.
🏛️ Understanding Team Management Governance
Team Management operates at the highest administrative level, focusing on user lifecycle management and global access control across the entire SpendCraft environment.
Key Distinction
While Workspaces control access to specific data projects, Manage Team governs a user's fundamental ability to interact with core system modules.
- User Provisioning Lifecycle: This feature manages the end-to-end process from sending an initial email Invitation to establishing a user as an Active Member. Administrators can track invitation acceptance status and manage expiry dates to maintain a secure perimeter.
- Role-Based Access Control (RBAC) Foundation: The permissions configured here (Read/Write for Modules) establish a user's maximum potential authority.
- Example: If a user is not granted Read access for the Agents module at this global level, they cannot view Agents in any Workspace, regardless of their individual Workspace membership.
- Security & Compliance: To support internal security audits and compliance, this module tracks critical safety fields such as MFA Enabled and provides the ability to instantly Delete or Revoke access.
📋 Core Governance Fields
| Field | Purpose |
|---|---|
| Status | Indicates if a user is Invited, Active, or Disabled. |
| Global Permissions | Defines the "ceiling" of access for modules like Analytics, Agents, and Taxonomy. |
| MFA Status | Verifies if Multi-Factor Authentication is active for the user's account. |
| Invitation Expiry | Manages the security window for new user onboarding. |
🔄 Administrative Best Practices
- Audit Regularly: Periodically review the member list to identify and remove "Invited" users who never completed their onboarding.
- Standardize Foundations: Set global permissions to "Read" for the majority of users, reserving "Write" permissions for designated System Administrators.
- Revoke Promptly: Ensure that offboarding procedures include the immediate Delete action in Manage Team to terminate all application-wide access.
🔗 Quick Links
Invite Team Member
Send invitations to new users to join your organization.
Update Permissions
Modify global module access for existing team members.
Track & Revoke Invitations
Monitor invitation status and revoke pending invites.
MFA
View and manage multi-factor authentication for users.
Delete Member
Remove users and revoke all access to the platform.