Asteria Docs

Users

Invitations, roles, seats, and the difference between deactivating and deleting.

Users in the console. Everyone in the organisation, their role, status, last activity and join date.

Roles

Three, and the middle one is the only decision.

RoleCan
OwnerEverything, including things no one else can undo
AdminManage users and configure organisation settings
UserStandard access to the application

Admins can do essentially everything in this guide. Give it to people who should be able to change what models exist and who is in the organisation, and not to somebody who just needs to see the usage numbers.

Change a role from the row's menu. You are asked to confirm, because it takes effect immediately.

Inviting

Invite User, enter an email, choose a role, send.

The invitation is emailed, and you get a link. Both matter:

The invitation link is shown once. It expires in 7 days, and resending generates a new one, which invalidates the old.

Copy it before closing the dialog if there is any chance the email will not arrive.

If the email cannot be sent, you are told so explicitly, with the link to pass on yourself. That case is worth taking seriously the first time you see it: it usually means email delivery is misconfigured for your domain, and every password reset will be failing the same way, silently, for people who cannot ask you.

Pending invitations lists what is outstanding, with expiry. Resend or cancel from there. Cancelling breaks the link immediately.

Seats

Your plan has a seat limit, shown as "4 of 10 seats used". At the limit you cannot invite, and the fix is to raise the plan or free a seat.

Freeing a seat means deactivating somebody, which brings us to the distinction worth getting right.

Deactivate, do not delete

Deactivate switches a user off. They cannot sign in, their seat is freed, and everything they made stays where it is: collections, agents, shared workspaces, the workflow that runs every Monday morning. Reactivating them restores access.

Delete permanently removes the person and all their data: conversations, collections, everything. It cannot be undone.

For somebody leaving the company, deactivate. Almost always.

Deleting takes their collections and agents with them, and if a shared agent pointed at a collection they owned, that agent stops working for everyone else. The console warns you, but the consequence lands on colleagues who were not in the room.

Before deleting anybody, check whether they own anything the team relies on, and transfer it first. See Sharing your work, and prefer making a project the owner of anything a team depends on, so this question stops arising.

Delete is the right call for a mistaken invitation, a test account, or a genuine erasure request.

What you cannot do here

Change somebody's email: it is their identity. Read their conversations. Sign in as them.

On this page