> ## Documentation Index
> Fetch the complete documentation index at: https://docs.athenahq.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Users & Access (Settings → Users)

> Manage who has access to the organization, its websites, and groups: view members and invites, change roles, move people between org/website scope, and administer custom roles and email-domain auto-join.

<Card title="Open in AthenaHQ" icon="arrow-up-right-from-square" href="https://app.athenahq.ai/settings/users" horizontal>
  `app.athenahq.ai/settings/users`
</Card>

## Purpose

The Users page is the central hub for team and access management within Athena. It allows organization owners and administrators to invite colleagues, assign them appropriate access levels, and control exactly which websites and features they can interact with.

Customers use this page to ensure their team members have the right level of access, whether that means full administrative rights across the entire organization, restricted read-only access to a single website, or specialized custom roles tailored to specific workflows. It also provides tools for streamlining onboarding, such as bulk CSV invites and email-domain auto-join.

## What's on the page

### Page header

Displays the "Users" title and a brief description of the page's capabilities, along with breadcrumb navigation to easily return to the main Settings menu.

### Toolbar

Contains a search box and a filter bar for narrowing down the roster. Includes an "Add user" button to initiate the invitation flow.

**Filters:**

* **Search:** Filters the list by matching an email address, first/last name, or an associated website URL.
* **Type:** Restricts the list to Organization-wide members, Website-specific members, or Group-specific members.
* **Role:** Restricts rows to specific system roles or your custom roles.
* **Status:** Filters by Active, Pending, Delivered, Bounced, or Expired states.
* **Website:** Filters for members/invites associated with a specific website (only visible if the organization has websites).
* **Group:** Filters for members/invites associated with a specific group (only visible if the Groups feature is enabled and active).

### People table

A unified roster of everyone connected to your Athena workspace, including organization members, website-only (external) members, group-only members, and pending invites.

**Columns:**

* **Member:** Shows the user's avatar, full name (or email if no name is provided), and email address.
* **Role:** An interactive dropdown to assign or change the user's role (e.g., Admin, Viewer, Editor, Billing, or custom roles). For the organization owner, this displays an uneditable "Owner" badge. If hovered over, the Owner badge shows the tooltip: *"Owner role cannot be changed directly"*.
* **Access:** Shows the scope of what the user can see. This displays "All websites" for organization members, a website logo/URL (or count of websites) for external members, or "Group: \[Name]" for group members.
* **Joined:** Shows the date the user joined, or an invite status badge (Pending, Delivered, Bounced, Expired) for pending invitations.
* **... (Actions):** A kebab menu offering row-specific actions like viewing details, moving the user's scope, or removing them entirely.

### Allowed email domains section

A configuration area where admins can set up approved company email domains. When a new user signs up using an email address ending in a verified domain, they automatically join the organization without needing a manual invite.

### Drilldowns

* **User Detail Drawer (Side Panel):** Clicking on a member's avatar, name, or selecting "View details" from the action menu opens a side drawer. It shows the user's profile, role, access scope, user ID (copyable), market landscape memberships, group memberships, and (for admins only) a recent activity audit log.
* **Add User Modal:** Clicking "Add user" opens a flow to invite one or more people. It includes a scope selector (Organization, Website, Group), fields for email and role, and a CSV import option.
* **Manage Roles Dialog:** Accessed from role picker menus, this dialog lists all system roles (view-only) and custom roles. It allows admins to create, edit, or delete custom roles and configure exact permissions using a detailed grid.

## What you can do here

### General & Bulk Actions

* **Add user:** Click the top-right button to invite colleagues. You can choose whether to invite them to the whole organization, specific websites, or specific groups.
* **Import CSV:** Inside the Add User modal, click "Import CSV" to upload a list of users. Tooltip: *"CSV columns: Email (required), Role (a role name like admin, viewer, editor, billing, or one of your custom roles; defaults to viewer)"*.
* **Add another:** Inside the Add User modal, adds another blank row to send multiple manual invites at once.
* **Bulk change role:** Select multiple user checkboxes in the table to reveal a bulk action bar, allowing you to assign a new role to all selected users simultaneously.
* **Bulk remove/revoke:** With multiple rows selected, click the remove action in the bulk toolbar to delete members or revoke pending invites in one sweep.

### Row-level Actions (via the ... menu)

* **View details:** Opens the User Detail Drawer to see a full profile and activity log.
* **Promote to owner:** Transfers organization ownership to the selected member. A confirmation warns: *"Are you sure you want to transfer ownership to \[name]? You will lose owner privileges and become an admin. This action cannot be undone."*
* **Restrict to specific websites:** Converts an organization-wide member into a website-only (external) member. Opens a dialog to pick which websites they keep access to.
* **Grant access to all websites:** Promotes a website-only member to a full organization member.
* **Remove / Leave organization / Leave website:** Removes the user from the workspace or allows you to remove yourself. Confirmation: *"Are you sure you want to remove \[name] from the organization? This action cannot be undone."* (Or, for self: *"Are you sure you want to leave this organization? You will lose access to all websites..."*).
* **Revoke invite:** Cancels a pending invitation.
* **Leave group / Remove from group:** Removes a group-only member from their assigned group.

### Role Management

* **Create new role:** Found at the bottom of role dropdowns. Opens a dialog to build a custom permission profile. Gated to Enterprise/Agency plans (opens an upgrade prompt otherwise).
* **View system roles:** Look at the uneditable permissions for default roles (Admin, Viewer, etc.).
* **Edit custom roles:** Adjust the permission grid for an existing custom role.
* **Delete custom roles:** Removes a custom role. Confirmation: *"Delete '\[role]'? Members and invites must not be using this role. This can't be undone."*

### Allowed Email Domains

* **Add Domain:** Opens a dialog to input a company domain (e.g., "acme.com") and select the default role auto-joined users will receive.
* **Verify DNS:** Shows the DNS TXT record you must add to your domain registrar to prove ownership.
* **Remove domain:** Deletes an auto-join configuration.
* **Change Default Role:** Updates the role given to future employees who auto-join using this domain.

### User Detail Drawer Actions

* **Edit name:** Click the pencil icon next to the user's name to edit their first and last name inline.
* **Change Role:** Select a new role directly from the dropdown inside the drawer.

## Data shown

* **Members & Invites:** Displays all individuals tied to your organization, pulled from your organization memberships, website-level assignments, and group alignments, alongside any pending invitations you've sent out.
* **Domain Auto-Join:** Displays your configured approved domains and their DNS verification statuses.
* **Activity Log:** A historical audit trail of the selected user's actions inside Athena (only visible to administrators looking at the detail drawer).

## Common workflows

**Inviting a new team member:**

1. Click the "Add user" button in the top right.
2. Choose the access scope (e.g., "Organization" for full access, or "Website" to limit them to specific brands).
3. Enter their email address and select a role (like Viewer or Admin).
4. Click "Send invite." They will appear in the table with a "Pending" status until they accept.

**Setting up domain auto-join:**

1. Scroll down to the "Allowed email domains" section and click "Add Domain."
2. Enter your company's domain (e.g., `yourcompany.com`) and choose a default role for new signups.
3. If your email matches the domain, it verifies automatically. Otherwise, click "Verify DNS" and add the provided TXT record to your domain registrar.
4. Once verified, colleagues can create Athena accounts using their work emails and will bypass the manual invite process.

**Restricting a member to a single website:**

1. Find the organization member in the roster and click the `...` menu on their row.
2. Select "Restrict to specific websites."
3. In the dialog, select the website(s) they should keep access to, and confirm. Their access column will update to show only those websites.

## Empty, loading, and error states

* **Empty:** If you apply filters that match no users, the table simply appears empty. If you haven't configured any auto-join domains, the section reads *"No domains configured."*
* **Loading:** While data is being retrieved, the table displays a skeleton outline with placeholder bars for names, emails, and roles, fading out toward the bottom of the list to indicate more data is loading.
* **Error:** Actions that fail (like a network timeout when changing a role or an invalid CSV import) will display a brief red error toast at the bottom of the screen (e.g., "Failed to update role").

## Linked from / links to

* **Linked from:** The main Settings navigation sidebar ("Users" or "People"). It can also be reached via deep links from group management panels elsewhere in the app (which automatically apply group filters).
* **Links to:** Upgrading plans (if trying to create custom roles without the proper plan) leads to the Billing flow. In-page actions open the User Detail Drawer and Manage Roles dialog.

## Common support questions

**Why can't I change the Owner's role?**
The organization owner must remain an Admin. To change their role, you first need to transfer ownership to someone else by clicking the `...` menu on the intended new owner's row and selecting "Promote to owner."

**Why does the "Create new role" button ask me to upgrade?**
Custom roles are a premium feature restricted to the Enterprise and Agency plans. If you are on a different plan, clicking this will prompt you to upgrade your subscription.

**I imported a CSV but some users were skipped. Why?**
The CSV importer will skip rows if the email address is invalid, if the user is already in the organization, or if the role provided doesn't match an existing system or custom role. The system will show a toast notification explaining what was skipped.

**Why do some users appear multiple times in the list?**
If a user has been invited exclusively to multiple *Groups* (rather than the whole organization), they may appear as distinct rows for each group they belong to.

**What happens if I filter by "Group"?**
Filtering by Group will temporarily hide all Organization-wide and Website-only pending invites, because those invite types do not carry group assignment data.
