Skip to content

Members and administrators

Every person in an organization is either an organization administrator or a member. A member can also administer one or more namespaces.

Authority What it covers
Organization administrator Members, invitations, policies, namespaces, Teams, access, private mirrors, storage, automation, billing, and audit. Full access to every repository without needing namespace membership.
Namespace administrator The members, Teams, base permission, grants, and automation tokens of one namespace, with full access to its repositories.
Member The namespaces they belong to, with the access those namespaces and their Teams grant.

Namespace administration never includes organization membership, billing, custom role definitions, remote-cache management, or another namespace. See namespaces for the complete list.

Open organization settings and select Members. The list shows each person’s role, state, and how many namespaces and Teams they belong to. Search by name or username, or filter by role and state.

Select Inspect to open a member page:

Section Shows
Overview Organization role, state, how they joined, and actions such as Make admin or Suspend
Namespaces The namespaces they belong to and why; add them to a namespace or remove a direct membership
Teams The Teams they belong to
Access Their direct grants and their effective access to every repository, with the source of each role

Every member can inspect their own row to see Your access.

Use Make admin only for people who need to govern the whole organization. Organization administrators keep their namespace memberships and Teams, and Team membership adds nothing to their access. Remove admin role returns them to a member with the namespaces, Teams, and grants they already have.

Ravenstash prevents removing or demoting the last organization administrator.

Organization administrators appoint namespace administrators from the namespace workspace: open Members, open the member’s actions, and choose Make namespace admin. A namespace administrator is always a member of that namespace. See namespaces.

Suspension pauses a member without losing their setup. Open the member’s actions and choose Suspend. Ravenstash immediately:

  • signs them out of the organization;
  • revokes their personal tokens for the organization; and
  • stops every repository and private-mirror permission they had there.

Their namespace memberships, Teams, namespace administration, and grants are kept but inactive. An administrator can still open the suspended member’s page: its Access section lists what they had and says it applies again after reactivation. Choose Reactivate to restore them together. Tokens revoked by the suspension stay revoked; the member creates new ones after reactivation.

Suspension does not affect organization-owned automation tokens.

Remove member ends the organization membership. The person loses access to the organization immediately, their namespace memberships, Team memberships, and grants are removed, and their personal tokens for the organization stop working. A member can leave on their own with Leave organization.

Organization administrators can cap how many active members the organization may have. Open Access, select Policies, and enter a Seat limit under Membership. Leave it empty for no limit. The card shows the current active members and pending invitations.

When the limit is reached, sending invitations, accepting an invitation, and reactivating a suspended member all fail until a seat is available.

Next, invite people or review namespace membership.