Teams and permissions
Rivets controls access with two roles and a set of teams. Roles decide who can administer the organization. Teams decide which repositories each member can use.
Roles
| Role | Can do |
|---|---|
| Owner | Everything a member can, plus: connect repositories and integrations, register and remove workers, manage teams, invite and revoke members, change organization settings and prompts. Owners always have access to every repository. |
| Member | Use the repositories their teams grant: create, watch, and steer tasks, open terminals, publish pull requests, and set their own account preferences. |
The person who creates the organization is its first owner.
Teams
Owners manage teams under Settings › Teams on web, Mac, and iOS.
A team has a Name, a set of Members, and a Repository access grant:
- Everything: all current and future repositories.
- Selected repositories: only the repositories you pick. Selecting none grants no repository access through this team.
To create one, choose Create team, fill in the fields, and choose Save team.
How access combines
A member’s access is the union of all their teams’ grants. They can use any repository granted by any of their teams. Removing a repository from one team does not remove access granted by another.
What access covers
Repository access applies everywhere: task lists and search, transcripts, changes and files, terminals, attachments, automations, MCP, and integrations. Someone without access to a repository cannot see its tasks at all. Assistant conversations are always private to their creator.
Invites
Owners invite people from Settings › Members by choosing Invite member and entering an email address. If email delivery is not configured, Rivets shows an invite link to share instead. The invitee opens the link, signs in or creates an account, and chooses Accept invite.
Each pending invite uses a seat until it is accepted or revoked. Settings › Organization shows seats used, counting members and pending invites. When all seats are used, you cannot send more invites. Revoke a pending invite from the invites list to free its seat. See Plans and seats.
When access changes
Changes to teams take effect right away:
- Open clients drop their cached data and reload the workspace. Unsent drafts can be lost during this reload.
- Live connections and direct terminal tickets are revoked. Some existing connections can last up to 60 seconds before they close.
- Revocation stops further access. It cannot take back content someone already copied or downloaded.
Workers are a trusted boundary
Teams are application permissions. They control what Rivets shows and allows through its API. They do not isolate what happens on a worker.
Other settings that are owner-only
- The organization image. Organization names cannot be changed yet.
- Merge method and auto-archive under Settings › Git workflow.
- Organization and repository prompts under Settings › Prompts.
- GitHub, Linear, and Slack under Settings › Integrations.