> ## Documentation Index
> Fetch the complete documentation index at: https://vida.io/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Members, Roles, and Account Access

> Give teammates the Vida access they need while keeping customer and Agent visibility appropriately scoped.

Vida membership belongs to an account. Invite people at the level where they work, then narrow child
account access when a reseller or organization member should see only selected customers or Agents.

## Choose the correct account level

* Most teams invite members to their **organization**.
* A reseller may invite staff who manage several customer organizations.
* A partner may manage resellers when that optional account level is enabled.
* Agent-specific access can limit an organization member to selected Agents.

Do not add a reseller or partner hierarchy only to solve ordinary organization permissions.

## Understand the roles

* **Owner:** Full account access, including billing. An account has one owner.
* **Admin:** Can manage Agents, members, settings, and integrations according to the account's
  enabled capabilities and access restrictions.

Invite each person with the least access that supports their responsibilities.

## Restrict access to child accounts

When the member panel shows **Allowed Orgs** or **Allowed Agents**, an empty list means the member can
access all available children. Add specific children when access should be restricted.

After changing access, verify it from the member's actual account view. Parent-account visibility
does not prove that the member sees the intended navigation or customer data.

## Remove access safely

Before removing a member:

* transfer ownership when applicable
* confirm another administrator can manage the account
* rotate credentials or external access the person controlled
* reassign operational responsibilities and alerts

Member access and API tokens are separate. Removing a person does not automatically rotate an API
token used by an integration.

## API and embedded access

Use API tokens for trusted integrations, not as substitutes for human membership. Create a
replacement token, verify it, move the integration, and then revoke the old token.

Eligible resellers embedding Vida should generate one-time user authentication tokens from a
trusted backend after confirming the user belongs to the intended customer.

<Note>
  Automating onboarding or access? See
  [Accounts, access, and customer onboarding](/docs/api-reference/platform-guides/accounts-access-and-onboarding).
</Note>
