Change roles and remove members
Change what someone can do, take their access away, or hand the organization to someone else.
Prerequisite Organization Owner or Organization Administrator. See Roles and permissions. Ownership transfer is Owner only.
The directory is the member list at /members. It carries every person in the organization and every team, and it is where roles change and memberships end. Adding people is a separate task, see Invite people to your organization.
1. The directory
Open Members at /members. The page holds two panels: Teams above, Members below.
The Teams panel is a table with three columns, Name, Handle, and Members. Selecting a team opens it, see Create and manage teams.
The Members panel is one row per person. Each row shows an avatar, the person's name, their public username in italics, and their organization role beneath.
A row for an invite nobody has accepted yet reads differently: the invited email address in italics, followed in amber by [Invite sent. Pending account creation], and no role line. See Pending invites.
Three controls sit at the right of every member row.
The directory searches teams and members together.
Row actions
| Action | Who can | Reversible | Effect |
|---|---|---|---|
| Machine access chip, reading All machines or showing the machines they are scoped to | Owner or Administrator. The chip does not render for anyone else | Yes | Opens the machine-access dialog for that person. See Limit which machines a member can see |
| Pencil | Owner or Administrator | Yes, change the role again | Opens Edit member role. See Change someone's role |
| Trash | Owner or Administrator | No, you re-invite and get a new membership | Opens Remove member. On a pending row this cancels the invite. See Remove a member |
Why can I see these controls without an admin role?
The machine-access chip is the only row control the dashboard hides from non-admins. The pencil and the trash render for every signed-in member, and IoTFlows enforces the role when the request reaches the platform. Treat the permission matrix as the rule, not the controls you happen to see.
2. Search members and teams
One field at the top of the page filters both panels at once. It reads Search teams and members or invite via email.
Type any part of a first name, last name, public username, or email address to filter the Members panel. Type any part of a team name or team handle to filter the Teams panel. Searching line 2 narrows both: teams whose name contains it, and nobody in the member list unless a name matches.
Matching members appear under the heading In this organization. When nothing matches, the panel reads No members match "line 2" or No teams match "line 2".
The search covers this organization only. To find someone who already uses IoTFlows but is not a member yet, open Add Member and search there instead, see Add an existing user.
3. Change someone's role
- Open Members at
/members. - Find the person, using the search field if the list is long.
- Select the pencil at the right of their row.
- Under Organization Roles, select a role. Hovering a role name shows its description.
- Select Edit role.
The dialog closes and a message reads "Member role changed to Organization Administrator", naming the role you picked. The new role applies immediately: the person does not sign out and back in.
IoTFlows serves the role list, so the options in this dialog come from the platform rather than from your organization. What each one can do is in Roles and permissions.
Changing a role. Change the role rather than removing and re-inviting.
Change a role rather than removing someone and re-inviting them. Re-inviting creates a new membership, and everything tied to the old one, work orders, board memberships, machine access, and chat history, has to be rebuilt by hand. Changing the role keeps the membership and swaps only what it can do.
Choose a role change over a removal whenever the person stays on site. A supervisor who now adds machines moves from Member to Administrator. A seasonal contractor who should read reports and change nothing moves to Observer. An operator who cannot classify downtime is almost certainly an Observer, see Which role for an operator?
4. Remove a member
Removal ends the membership. Do the two things below first, because neither is recoverable from the directory afterwards.
Before you remove anyone
Reassign their open work orders. Removal leaves those work orders open and unassigned, and an unassigned work order is one nobody is watching.
Reassign from the work order itself, see Update, discuss, and close a work order. Then check whether they own anything only they administer, which the dialog asks about in step 5 below.
- Open Members at
/members. - Find the person.
- Select the trash at the right of their row.
- In the Remove member dialog, check the name, username, and email against the person you meant. Select Confirm remove.
- If a second step appears, answer it. See If they are the last administrator.
A message reads "Member has been removed" and the row leaves the directory.
Removing a member.
On a row that still reads [Invite sent. Pending account creation], this same dialog is how you cancel the invite. The wording does not change, so the dialog says "Remove member" and reports "Member has been removed" about an address that never accepted.
If they are the last administrator
If the person is the only administrator of something inside the organization, Confirm remove does not finish. The dialog swaps to a second step reading Maria Lopez is the last administrator of at least one resource in this organization. and asks Would you like to: with two options.
| Option | What it does | Choose it when |
|---|---|---|
| Keep resources and remove member | Removes the membership and leaves everything they administered in place | Almost always. The resources stay, and you give someone else administrative access to them afterwards |
| Delete all resources and member | Removes the membership and deletes everything they were the last administrator of | You are cleaning up a test membership, or you have confirmed nobody relies on those resources |
Select one, then select Confirm. The message is the same, "Member has been removed".
Default to Keep resources and remove member. Deleting is not reversible from this dialog, and the dialog does not list what it is about to delete. Something nobody noticed this person administered is how a plant loses a setting it was relying on.
5. Transfer ownership
The Owner is the role that pays for IoTFlows and the only one that can hand the organization over. Every organization has at least one, see Owner-only actions.
The dashboard has no button labelled Transfer ownership. Ownership moves through the role dialog: the current Owner gives another member the Organization Owner role, using the steps in Change someone's role, and then takes Organization Administrator for themselves. An Administrator has the same authority minus billing, so the person handing over loses nothing else.
Transferring ownership. An Owner cannot leave without doing this first.
Transfer ownership before the current Owner's last day, not after. An Owner cannot leave the organization while they are the only Owner, and an organization whose Owner has gone cannot pay an invoice or clear a suspension. If that has already happened, contact IoTFlows.
6. What removal does
Removal is total. The person loses the organization everywhere it appears: the web dashboard, the mobile app, every board, every team, and every chat inside it. They keep their IoTFlows account and any other organization they belong to, see Switch organizations.
What the organization keeps:
- Their work orders stay open and become unassigned. The work is not deleted and not closed. Nobody owns it, and nothing in the product flags it, which is why reassigning before removal matters.
- Their history stays. Downtime they classified, jobs they ran, and comments they wrote are still attributed to them.
- Whatever they administered stays, unless you chose Delete all resources and member at the last-administrator step.
- The removal is recorded. See Review the organization audit log.
What does not come back:
- Machine access. A membership you re-create starts with access to all machines, and any restriction you had set is gone.
- Team membership and board membership. Re-add them by hand.
- The membership itself. Re-inviting creates a new one, which is the whole reason to change a role instead.
Someone says a machine disappeared
That is usually a machine-access change rather than a removal, because a restricted member keeps their sign-in and only loses the machines. See Limit which machines a member can see.
See also
How to add people to an IoTFlows organization, by email or as an existing IoTFlows user. One dialog, Add Member, handles both and is reachable from the member directory at /members and from the members control in the dashboard header. Typing a complete email address offers an emailed invite; typing a name or username searches every IoTFlows account. Every invite carries an organization role, and the role list is served by IoTFlows. A pending invite shows in the directory as the invited email address followed by [Invite sent. Pending account creation] until the person creates their account. There is no resend action: to reissue an invite, remove the pending row and invite the address again.
How to restrict an IoTFlows member to specific machines. Machine access is a per-person list of allowed assets, managed from the member directory at /members: each member row carries a control that reads All machines when the list is empty, or a stack of machine avatars when it is not. Opening it shows the Machine access dialog, where tapping a machine grants or revokes it immediately, with no Save step. An empty list is the default and means the member sees every machine. A restriction narrows everything, including the machine pickers on reports and work orders, so a member reporting that a machine disappeared has usually been restricted. Only an Organization Owner or Administrator can see or change the control.





