FlowFlow

Team and permissions

Flow isn't meant to stay a one-person tool once you're running more than a project or two. The Team page is where you bring other people in and decide how much of the dashboard they can see and touch.

The three roles

  • Owner: full access to everything, and the only role that can't be removed if it would leave the org without one. The person who signs up first becomes the owner.
  • Admin: nearly the same as Owner day to day, can manage nodes, Git providers, team members, and see every project. The practical difference only shows up around ownership transfer edge cases.
  • Member: can only see and work in projects they've specifically been given access to, rather than everything in the org by default. This is the role for someone who should only touch one client's work, not your entire instance.

Owners and admins can change anyone else's role from a simple dropdown right on the Team page, changes take effect immediately. You can't change your own role, and Flow won't let you demote or remove the last remaining owner, on purpose, there always needs to be someone who can get back into everything.

Inviting someone

Enter their email and pick a role, and Flow creates an invite that's good for seven days. It gives you back a link to send them yourself, Flow doesn't email it on your behalf, so paste it into whatever you'd normally message them on. Pending invites are listed with their expiry and a Revoke button if you change your mind before they accept.

Invites are for brand new people specifically, if that email already has a Flow account anywhere, even in a different org on the same instance, the invite is rejected rather than silently doing something unexpected. When someone opens their invite link, they see which org and role they're joining, set a name and password, and they're signed in immediately, no separate signup step.

Project-level access, for members

Since a Member only sees projects they've been granted, an admin needs to explicitly hand that out. Open a project, its Access tab (visible to admins only) lets you grant or revoke individual members. Owners and admins never need to be added this way, they already see every project regardless. This is the tool for the actual scenario that probably brought you here in the first place: a handful of clients, and you want each person on your team to only see the clients they're actually working on.