Skip to content

Invite members and set roles

Invite people, set their workspace role, deactivate leavers and build a role hierarchy from the Organization tab. Admins open it from Admin in the sidebar; managers open the same page from Manager, with fewer controls.

Every member is an admin, a manager or a member. Admins can change every setting on the Admin page. Managers see the Overview, Organization and Email Templates tabs and can manage tags, but they can’t change roles or send invites. Members don’t see the Admin page at all.

The Role column in the Members list sets what a person can do. You set where they sit in the org chart, which decides whose records they can see, separately under Role hierarchy.

Only an admin can create invites. To invite a person:

  1. Open Admin, then the Organization tab.
  2. Under Invitations, click Generate Invite.
  3. Type their address in Email (optional), or leave it empty for an open invite anyone can use.
  4. Pick Member, Manager or Admin under Role.
  5. If record sharing is on, pick a Position in the org chart.
  6. Tick Email this invite link to the recipient if you typed an address and want Mesy to send it.
  7. Click Create.
  8. Copy the link that appears; Mesy shows it even when it emails the invite.

An invite expires after 7 days and works once. The pending list shows each invite’s Email, Role and Expires date, plus its Position when record sharing is on. Remove an invite from its row to revoke it. An open invite without an email can’t create an admin account, so type the address when you invite an admin.

An admin changes a member’s role from the Role dropdown on their row. You can’t change your own role. Mesy refuses to demote or deactivate the last active admin. It also refuses to deactivate the last active user, so someone can always sign in.

To remove someone’s access:

  1. Find them in the Members list.
  2. Click Deactivate on their row.
  3. Confirm with Deactivate.
  4. Their Status changes to Inactive and their open sessions end straight away.

Admins see a Require two-factor authentication switch under the members list. Turn it on and confirm with Require 2FA in the dialog. Nobody is signed out; each member without a second factor sets one up at their next sign-in before they can use Mesy. While the switch is on, a member can’t remove their last second factor.

Admins and managers also see a 2FA column showing Enrolled or Not enrolled for each member. A passkey or an authenticator app both count as enrolled.

The Role hierarchy section is admin-only. A role is a position in your org chart: once record sharing is on, superiors see their subordinates’ records. To create the first role:

  1. Click Create root role.
  2. Type a Name, such as a team or region.
  3. Leave the Slug Mesy fills in, or edit it.
  4. Click Create role.
  5. The role appears in the tree with a member count of 0.

Each role has a menu with Add sub-role, Assign users, Rename, Move and Delete. In Assign users, click Assign next to a member, or Move here if they already sit on another role, then Done. Deleting a role also deletes its sub-roles and unassigns their members, who fall back to their workspace role.

The Record sharing switch stays off until at least one role exists with one active member assigned to it. Turning it on can hide records from members immediately; admins always see everything.