Access & security
Team and roles
Invite people to your workspace, give them a role, and share individual apps with collaborators.
A workspace has members, and each member has one role. You can also share a single app with a collaborator as a viewer or editor.
Roles
| Role | What they can do |
|---|---|
| Owner | Everything: org settings (Cloud, Access, Domains, Audit log), billing, members, all apps. |
| Admin | Manages members, all apps and approvals. Can view billing but not change it. |
| Member | Creates apps and works on apps they own or were added to. |
| Billing | Manages billing. Can't create or manage apps. |
Some details:
- Org settings (Cloud, Access, Domains, Audit log) are owner-only.
- Only an owner can make someone an owner, change an owner's role, or remove an owner.
- A workspace always has at least one owner. You can't demote or remove the last one.
- Billing-role members can't be added to apps as collaborators.
Check your own role from the CLI:
elula whoami
Invite people
Owners and admins invite people from the Team page.
- Click invite and choose a role: member, admin or billing.
- Enter an email address, or leave it blank to make a link.
- Send or copy the link.
How invite links work:
- With an email, Elula emails the link. Only that Google account can accept it.
- Without an email, you get a one-time link that anyone can use.
- Links work once and expire after 7 days.
- Elula doesn't store the link, so copy it when it's shown. Resend makes a new link and the old one stops working. Resend also works on expired invites.
- Inviting the same email again replaces the earlier invite.
You can't invite someone as an owner. Invite them with another role, then promote them on the Team page.
Auto-join
With auto-join on, anyone who signs in with a Google account on your verified team domain joins the workspace as a member, with no invite.
- Auto-join needs a verified team domain. See Private and public apps.
- Owners turn it on or off in Org settings → Access.
- Changing the team domain turns auto-join off.
- Personal email domains such as
gmail.comnever auto-join.
Change roles and remove people
On the Team page, owners and admins can change a member's role or remove them. Owners can also use Make someone else an owner.
When you remove someone:
- Apps they owned in this workspace are reassigned to you, so nothing is left without an owner.
- They lose collaborator access to this workspace's apps.
- Their apps and access in other workspaces are not affected.
Collaborators on an app
Share a single app with someone in your workspace without changing their workspace role.
| Collaborator role | Access |
|---|---|
| Viewer | Can see the app in Elula, but can't deploy it or change it. |
| Editor | Can work on the app, including deploys and settings. |
The app's owner and workspace owners and admins can add collaborators. The person must already be a member of the workspace and must have signed in to Elula at least once.
elula collaborators list elula collaborators add alice@company.com --role editor # --role viewer|editor, default viewer elula collaborators remove alice@company.com
Approvals
Owners and admins review requests on the Approvals page or with elula approvals. Requests include members asking to make an app public. See Private and public apps.
Several workspaces
You can belong to more than one workspace. Switch the one you're working in from the dashboard's workspace switcher or the CLI:
elula org list elula org switch <slug-name-or-id>
The active workspace is saved to your account, so the dashboard and CLI use the same one.
Audit log
Owners can see who did what in Org settings → Audit log. It records changes such as invites, role changes, removals, access policy changes, approvals and cloud connections.