# Manage teams and permissions

Teams keep domains, credentials, email logs, suppressions, webhooks, and credits together while controlling who can manage them.

## Understand team scope

When you switch teams, Prontuno changes the resources and credit balance shown in the dashboard. Before creating a domain, credential, webhook, or suppression, confirm that the intended team is active.

Your personal team is designed for your own resources. Shared teams let several people work with the same sending setup.

## Roles

- Role | Access
- Owner | Full access to team settings, members, billing, domains, credentials, suppressions, and webhooks.
- Admin | Can update the team; invite people; manage billing, domains, API keys, SMTP credentials, manual suppressions, and webhooks.
- Member | Can work with team resources but cannot manage members, billing, credentials, or webhook settings. Members can inspect and retry webhook deliveries.

The Owner role cannot be assigned through a normal invitation. Invite people as Admin or Member according to the access they need.

## Create a shared team

1. Open **Settings**, then **Teams**.
2. Select **New team**.
3. Enter a clear team name.
4. Create the team and switch to it before adding resources.

Use a shared team for a company, product, environment, or business unit that needs its own resources and credit balance.

## Invite a team member

1. Open the team from **Settings > Teams**.
2. Select **Invite member**.
3. Enter the person’s email address.
4. Choose **Admin** or **Member**.
5. Review the displayed permissions and send the invitation.

Invitations expire after three days. Cancel a pending invitation if it was sent to the wrong address or is no longer needed.

## Team security practices

- Give each person their own account; do not share dashboard logins.
- Assign Member unless the person needs administrative access.
- Limit credential and billing access to trusted Admins.
- Enable two-factor authentication for every user.
- Remove former staff and contractors promptly.
- Revoke or rotate credentials after a member with secret access leaves.
- Use separate credentials for each application and environment.

## Leave a team

A non-owner can leave a shared team from the Teams settings page. If it is the active team, Prontuno switches the user to an available fallback team. Confirm that someone else retains the access needed to operate the integration before leaving.

## Next steps

Team usage and resource limits are visible under **Usage**. Billing administrators can also review [credits and billing](https://prontuno.com/docs/account-billing/credits-and-billing/).
