# Create and manage staff accounts

## How team access works

New team members get a **staff account**: a company account that belongs to your workspace. You create it, hand out the credentials and stay in control of the password, active sessions and offboarding. There is currently no email invitation; the staff account is the one way in.

**Prerequisite:** only owners and admins can create accounts. If you do not see the button, check your role under *Settings > Members*.

---

## Create a staff account

1. Go to **Settings > Members**.
2. Click **Create staff account**. You land on a dedicated page.
3. Enter the name and the company email. The email is the account's login.
4. Set a password or generate a secure one with a single click.
5. Choose the role (see the table below).
6. Optional: set a monthly credit allowance.
7. Click **Create account**.

After creation the page shows the credentials **once**. Pass them on securely, for example in person or through your password manager. You can reset the password at any time later.

---

## Roles and permissions

| Role | Use tools | Manage team | Billing | Settings |
|---|---|---|---|---|
| Admin | All active tools by default | Yes | Yes | All |
| Member | All active tools by default | No | No | Profile only |
| Observer | Read-only | No | No | Profile only |

"By default" means: that is the preset, and you can change it. Which tools a role actually sees is set under *Settings > Roles*, and exceptions for a single person in the **Permissions** section of their profile. See [Roles and permissions](/help/howto/rollen-und-rechte).

**Admin** has full access to every workspace function. Only people you trust should get this role. Recommendation: at most two or three admins per office.

**Member** is the default role for team members who work independently. They use all activated tools and manage their own entries.

**Observer** is the restricted role for back office or interns: reading yes, starting tool runs no.

---

## Seats and paid seats

Every plan includes free seats (your owner seat counts as one). Beyond that you can subscribe to additional seats for 19 euros per month, up to your plan's ceiling:

| Plan | Included seats | Ceiling |
|---|---:|---:|
| Compact | 1 | 5 |
| Standard | 3 | 10 |
| Max | 5 | 20 |

Once all seats are taken, the **Subscribe to another seat** button appears under *Settings > Members*. After subscribing you go straight into account creation.

**Paid seats bring their own credits:** a subscribed seat includes 250 credits per month that belong permanently to the account on that seat. You do not have to allocate anything from the team pool. If you like, you can add a top-up from the pool (example: 250 base + 100 top-up = 350 credits per month).

---

## Managing and offboarding an account

**Manage** next to each employee account opens its detail page:

- **Reset password** ends all active sessions automatically.
- **End sessions** signs the person out everywhere.
- **Offboard** clears the seat: personal data is deleted and sign-in is blocked. The seat stays and can be set up for the next person. Until then it keeps costing.
- **Delete seat** removes the account permanently. For a paid seat, the seat fee ends with it.

Records the person created (in the credential vault, for example) stay. Only their access is withdrawn.

---

## Operations you cannot undo

Three things cannot be reversed on a member: **transferring ownership**, **offboarding** someone, and **deleting a seat**. These do not run through a single prompt but through their own step-by-step flow. You start it from the danger zone on the member's detail page.

The flow asks, in order:

1. **Scope.** What exactly happens and what stays untouched. For example: when offboarding, the seat remains and keeps costing until you set it up again or delete it.
2. **Consequences.** You confirm each one separately. Only once all are confirmed does the flow continue.
3. **Identity.** You prove who you are with your second factor. You switch to sign-in briefly and come straight back here. The proof lasts 15 minutes; after that you are asked again.
4. **Consent.** Ownership only, see below.
5. **Execute.** You type the person's name and confirm.

An unfinished operation expires: after 30 minutes for offboarding and deletion, after seven days for an ownership transfer. You can cancel it at any time.

**If something changes, the flow stops.** Say you start a deletion and a colleague changes that person's role in the meantime. The flow then shows you what changed and you start over, so you always decide about the state you actually read.

### Offboarding and deleting: passwords in the vault

If the person opened credentials in the vault, the flow shows how many of them have **not** been rotated since. They still know those passwords, and the platform does not rotate them for you. When deleting, this is your last chance: afterwards the list is gone, because it belongs to the account.

### Ownership: the other side has to agree

Ownership is a responsibility, not an award. Whoever takes it takes on billing, the plan, and the ability to delete the entire workspace. Obligations like that cannot simply be handed to someone.

So after you prove your identity, a **request** goes to the future owner, both as an in-app notification and by email. Neither triggers anything: they lead to a page where the person has to be signed in and prove their own second factor. Only then can they accept or decline.

Once they accept, you get a notification and finish the transfer. Because days can pass between request and completion, you prove your identity a second time at that point. After the transfer you are an administrator, and only the new owner can hand ownership back.

When offboarding or deleting, the affected person is **not** asked. That would be a veto over their own departure.
