Key concepts
Members
Members are the people who work inside a workspace. Each member row shows the Member and their Permission — for example, a member named AD Admin with permission Owner, or a member named DE demo1 with permission Read only.Invitations
Invitations are how new members join a workspace. A pending invitation grants no access until it is accepted.Permission groups
Permission groups bundle a set of permissions under one name. Assigning a group to a member grants exactly the permissions the group contains.The Members screen
The screen has three tabs:Invite a member
1
Open the Members tab
Navigate to Settings → Members.
2
Click Invite member
The Invite member button opens the invitation form.
3
Enter the email address(es)
Provide one or more email addresses for the people you want to invite.
4
Choose a permission group
Select the permission group the new members should receive.
5
Send the invitation
Submit the form. An invitation is sent to each address; it appears under the Invitations tab until accepted.
Can I resend or cancel an invitation?
Can I resend or cancel an invitation?
Yes. Open the Invitations tab to see all pending invitations. Each pending invite can be resent (for example, if the email was lost) or cancelled (to revoke the invite before it is accepted).
Manage members
In the Members tab, each row has a menu with two actions:- Change permission — re-assign the member to another permission group.
- Remove — remove the member from the workspace. Removed members lose access immediately.
Create a permission group
1
Open the Permissions tab
Navigate to Settings → Members → Permissions.
2
Search or browse
Use the Search permission groups… box to find existing groups.
3
Click Create group
The Create group button opens the group editor.
4
Name the group and select permissions
Give the group a name and choose the permissions it grants.
5
Save the group
Submit the form. The group is now available when inviting members or changing permissions.
Built-in permission groups
OASM ships with three built-in groups. In practice, the Admin group can view and update workspace information, change workspace configuration, manage the workspace API key, add or remove members, manage invitations, create and modify workflows and permission groups, and view and modify scan targets. The Read only group is limited to viewing invitations and discovered assets.Best practices
- Start every member with the least privilege they need and escalate only when required.
- Reserve Owner System and Admin for a small set of trusted members — these groups can delete the workspace and manage its configuration.
- Create dedicated groups for recurring team roles instead of assigning permissions ad hoc.
- Review pending invitations and members regularly; cancel stale invites and remove members who left.
- Keep the workspace Read only group for members who only need to monitor results.
Related
Users and roles
Understand platform roles such as admin, user, and bot
Workspace
Understand the isolated tenant members operate in
API keys
Manage the workspace API key for programmatic access
Audit log
Review membership and invitation activity
