4. Onboard your team
15 minutes. By the end you'll have invited two teammates into your organization with appropriate roles, and you'll understand how the role + permission model fits together.
What you need
- Organization admin role (or a custom role with
members:create+roles:read) - Email addresses for the people you're inviting
Step 1 — Decide on roles
DT Edge Platform ships with a few built-in roles per organization, and you can define custom ones. Before inviting anyone, decide what each person needs:
| Built-in role | Typical use | Can do |
|---|---|---|
| admin | Co-owners | Everything in the org, including roles + members |
| developer | App engineers | Install / upgrade / uninstall apps; view alarms; edit registries |
| operator | On-call / SRE | All of developer + manage alarms + acknowledge fires |
| viewer | Stakeholders / managers | Read-only across most pages |
Your install may have customised this list — check Organizations → Your org → Roles to see exactly what's defined.
Step 2 — Open the members page
Sidebar → Organizations → click your org → Members tab.
You'll see a list of current members with their email + role. Click Invite Member at the top right.
Step 3 — Send the first invitation
In the drawer:
- Email — the person's address. They don't need an account yet; the invitation flow handles signup.
- Role — pick from the list. Stick with built-ins for the tutorial; custom roles are a follow-up.
- Expires in — how long the invitation link is valid. Default is 7 days; shorten if you want to nudge people to act fast.
Click Send. DT Edge Platform generates a one-time token, emails the
person a link of the form
https://your-host/invite/<token>, and shows the new pending
invitation in the list.
Step 4 — What they see
When the invitee clicks the link:
- If they don't have an account yet, they're walked through sign-up (name + password + optional 2FA). Their email is pre-filled and locked to the address you invited.
- If they already have an account, they log in normally and the org membership is added to their account on first login.
- Either way, they land on your org's dashboard with the role you assigned.
Step 5 — Send the second invitation
Repeat Step 3 for a second teammate. Try a different role this
time — if the first one was developer, make this one viewer
to see the contrast in how the UI behaves for them.
Step 6 — Verify by switching context
If you can, ask one of them to log in. They should see:
- The organization in their org selector (and only that org if they're not a member of others)
- Sidebar entries gated to their role — a
viewerwon't see the "Add" buttons in Edge Instances / Marketplace / Alarms; anadminwill see the Members + Roles tabs
Managing the membership later
The Members page also lets you:
- Change a member's role — actions menu on the row → pick a new role
- Remove a member — actions menu → remove. Their personal account stays alive; only the org membership goes away. They immediately stop seeing this org in their selector.
- Cancel a pending invitation — if they haven't clicked the link yet, you can revoke it. Pending invites live in their own list right under the active members.
When to use custom roles
The built-ins cover ~90% of cases. Reach for custom roles when:
- You need to grant exactly one extra permission ("can install apps but not edit registries") and the built-in tier above would over-grant
- Your organisation has a domain-specific division (e.g. "alarms-only role for the SRE rotation")
Open Organizations → Your org → Roles → Add role to define one. Pick the org-scoped permissions to grant; click save; assign it via the same Members page next time someone joins.
What's next
- How-to: manage members and roles — for "I just want to change one thing"
- How-to: set up 2FA — gentle nudge for your team to do this
- Reference: permissions catalog — every permission, what it gates