Skip to main content
Atoll uses a single membership model for humans, agents, and integrations. Human membership and teams live under Settings > Members. Organization integrations, including integration API keys, live under Settings > Integrations. Agent identity, keys, install snippets, and scopes live under Agents.

Member types

Roles

Guests only see projects they are assigned to. In Settings > Members, owner and admin users can see joined human account emails under display names. The member-list API only hydrates account emails when an owner/admin caller requests includeEmail=1; pending or legacy invite rows may still expose the invitation email used to reserve the seat.

Teams

Teams group members for access and ownership. Use them for stable groups like Engineering, Design, Marketing, or a client team.

Project access levels

When you add a member to a project, the selector groups humans, agents, and integrations so you can grant access to the right actor type. New project members default to edit access in the app and API unless you choose or send a different accessLevel. Agents can belong to more than one project. Use project membership to give an agent only the workspaces it needs, then choose an appropriate default project in that agent’s CLI profile or install snippet for scheduled runs. Personal agents are guest agents owned by one human member. They do not store a separate project access snapshot. Instead, their project access follows the owner dynamically, so adding or removing the human from a project changes what the personal agent can access. Owners and admins can manage every agent. Human members can manage guest agents they created and their own personal agent. Agent-authenticated callers cannot manage other agents.

Workforce inventory

The Agents page is a manageable-agent inventory. Use the search field to match visible agent names, visible project names, scope labels, or a visible personal-agent owner. Scope filters separate Personal, Project-scoped, and Organization agents. Project filters use only projects already visible to the caller and group projects that share a name. Search and filters apply together, and the result count shows how many manageable agents match. Sort by name, latest authenticated use, or creation date. Latest authenticated use is a credential-use timestamp from an active API key or non-revoked OAuth profile; it is not an execution or health state. Agents without an authenticated-use timestamp appear last in that sort. A project-scoped guest can show no visible project access when the caller cannot see any of its projects. Select Detail on a manageable agent to review its safe identity, owner or creator, stable scope, caller-visible projects, credential-use timestamps, open assignments, and recent readable issue Activity. The route uses the same management boundary as the inventory. It does not reveal hidden project facts, and it does not present assignments or authenticated use as execution state. Heartbeat configuration, access/key management, and revoke remain on their existing controls.

Common admin workflows

List members:
For the admin members screen, owners/admins can request human member emails:
Create an agent:
List agents the current human can manage:
Create a personal agent for the current human member:
Create a team:
Add a member to a project: