---
kind: question
zz: "0.4.0"
updated: 2026-10-07
state: live
rules: https://zriz.io/llms.txt
---
# Members and roles of a zriz org

An admin invites a person by email with `zz members invite`. An org has three roles: admin, member, and viewer. There is no other role.

## How do I invite a person? {#invite}

An admin does `zz members invite <email>`. The invite gives the role member and stays open for 7 days.

Add `--role admin` or `--role viewer` for a different role.

The field `emailed` of the reply tells how the person gets the join link:

| `emailed` | What to do |
|---|---|
| `true` | Nothing. The cloud sent the join link to the address. |
| `false` | Give the value of `link` to the person. The cloud sent no email. |

A new invite for the same address revokes the invite that was open. The error `already-member` means that the address is a member of the [org](https://zriz.io/docs/words.md#org) now.

## What can each role do? {#roles}

An admin can do each action. A member can start runs but cannot manage members or runner tokens. A viewer can only read.

| Action | admin | member | viewer |
|---|---|---|---|
| Read the runs, the runners, and the members | Yes | Yes | Yes |
| Start a run | Yes | Yes | No |
| Make or revoke a runner token | Yes | No | No |
| Invite a person, cancel an invite | Yes | No | No |
| Change a role, remove a member | Yes | No | No |

A command that the role does not permit gives the error `forbidden`.

## Where do I see the members and my role? {#list}

`zz members` lists the members with their roles, and the open invites. Each role can do this command.

## How do I change the role of a member? {#change-role}

An admin does `zz members role <email> <role>`. The role is `admin`, `member`, or `viewer`.

An org must keep one admin. A change that leaves no admin gives the error `last-admin`.

When an admin gets a lower role, the cloud revokes the open invites that this person made.

## How do I remove a member? {#remove}

An admin does `zz members remove <email>`. The person is no longer a member, and the cloud ends the web sessions of the person.

The API keys of the person stop at the next request. The cloud also revokes the open invites that this person made.

The last admin cannot be removed: the error is `last-admin`.

## How do I cancel an invite? {#cancel-invite}

An admin does `zz members uninvite <id>`. The id is the field `id` of the invite in the reply of `zz members`.

The join link of that invite then does not work.

## What does an invited person see? {#join}

The join link opens a page with the heading `Join <org name>`. The page shows the address and asks for a new password.

The person clicks `Join`. The person is then signed in as a member of the org, with the role of the invite.

Two cases stop the person:

| The page says | Cause |
|---|---|
| `This invite link is not valid.` | The invite was used, was cancelled, or is older than 7 days. Make a new invite. |
| `This email already has a zriz account.` | One email belongs to one org. Ask the admin to invite a different email of yours. Then add the login: `zz login --add` |

## How do I work in two orgs? {#two-orgs}

Use two emails. One email is one account in one org.

1. Add the second login: `zz login --add --as personal`. Sign in with the second email in the tab.
2. List the logins: `zz switch`
3. In a work folder, the project selects the login. `.zriz/project.json` has `org`, and `zz` uses the login of that org. Each command shows the org it used.
4. Out of a work folder, `zz` uses the current login. Change it: `zz switch work`
5. For one command, use `--org` with a login name or an org id: `zz --org personal runners`
6. For a shell, set the variable `ZZ_ORG` to a login name or an org id: `export ZZ_ORG=personal`. `--org` wins over `ZZ_ORG`.
7. Rename a login: `zz switch --rename personal home`
8. Remove one login: `zz logout personal`. Remove each login: `zz logout --all`.

The reply of a command has the key `org`, with `login`, `org-id`, and `source`. `source` is `flag`, `zz-org`, `project`, `current`, `only-login`, or `api-key-env`.

A command with the wrong org stops with `org-mismatch`. To move a project to a different org, change `org` in `.zriz/project.json`.
