# The team and roles

Add the people who reach your brand's console, hand them a password, and remove access from those who leave.

Source: https://docs.sealtrust.io/en/console/reglages-equipe/

---

This tab lists the people who can open your brand's console, and is where you add or remove them. An invitation does not go through a confirmation email: you enter the address, the console prepares a password, and you are the one who passes it on to the person concerned. The number of members is capped by your plan.

![The Team tab, with the member list and the invite button](/console/reglages-equipe.en.webp)

## What the screen shows

- A quota badge. When the plan caps the team, it gives the current member count over the allowed maximum, in the "{current}/{max} users" shape. When the plan sets no cap, it gives the count alone.
- The invite button, above the list.
- The member list, with a removal button on each active row. Rows already deactivated carry none.
- In the invitation window, a password prepared for you, 16 characters drawn from an alphabet that leaves out ambiguous characters (l, o, I, O, 0, 1).

## What you can do here

- Open the invitation window and enter an address, a first name and a last name.
- Keep the prepared password, or type one yourself.
- Copy the password. If copying fails, the screen reveals it so you can write it down.
- Remove a member. Their row stays in the list, marked inactive.

## What controls access

- The cap comes from your plan. It is reached as soon as the current member count equals the maximum.
- When the cap is reached, the invite button is disabled and a tooltip on hover recalls the plan maximum.
- The button in the invitation window stays disabled while the address or the password is empty.
- Before creating the account, the server checks that the plan is active, then that the user quota is not reached.
- The invited person is created with the administration role, and their address is marked as verified. Email confirmation only concerns public sign-up.
- Removing a member does not delete their row. The account is deactivated and its still valid tokens are revoked, so a session open elsewhere stops.

## What the screen refuses

- An address already used by another account is refused, on the grounds that a user with that email exists.
- A password shorter than 8 characters is refused when the account is created.
- Deactivating yourself is refused.
- Deactivating someone who does not belong to your brands is refused, on the grounds that the user is not part of your team.
- Going over the quota is refused by the server, which returns the resource concerned, the current count and the maximum. The screen then shows an invitation to move to a higher plan.
