Two different questions get confused constantly. Your role decides what you can manage. A document's access level decides what you can read. Keeping those apart saves a surprising amount of confusion later, because someone can be an administrator of one group and an ordinary reader in another, on the same account, on the same afternoon.
The five roles
| Role | What they can do |
|---|---|
| Visitor | No account. Chat with public documents, open public collections and shared conversations. No dashboard. |
| Registered user | The above, plus whatever their organizations share with members. Manages their own profile, sees no admin areas. |
| Owner admin | The above, plus the dashboard for their organization: documents, collections, categories, branding, settings, users. |
| Primary admin | One per organization. An owner admin plus billing, and the only person (aside from super admins) who can invite or promote other owner admins. |
| Super admin | Docutrain's own platform operators, across every organization. |
There are four ways to end up with one. Signing up through Create a group makes you owner admin and primary admin of a new organization once your email is verified. An invitation carries whatever role the inviter chose. An approved join request always grants registered member, never anything higher. And a primary or super admin can change someone's role directly.
Two rules hold everywhere, and both exist to prevent the same category of accident: you cannot downgrade your own super admin role, and nobody can delete or ban their own account.
Getting into a second group, and out of one
You do not have to wait to be invited somewhere, and you are not stuck in a group you have finished with. Both live in the Owner groups panel on your profile, which counts what you have at the top ("2 groups · 1 pending") and gives each row a role badge and a Leave button.
Request access opens two tabs. Find a group searches organizations whose admins marked them discoverable. Private group is for everything else: type the exact group address and send a request. That tab also carries Have an invite code?, which is the faster road, since a code joins you immediately while a request waits for a human.
Leaving is one button and a confirmation. Access goes at once, and you can ask again later. The exception is the primary admin, whose Leave button is disabled with a plain explanation: transfer the role to someone else first. An organization is never left without a billing contact by accident.
The notice that is easy to miss
Two different situations put a stranger in front of you, and they show up in different places.
Someone who signed up against your organization but has not been granted access appears as a Pending row in your Users table. Someone who already has an account and asked to join appears in a separate Join requests section above the table, with their name, when they asked, and any note they left. They are not members yet, so they cannot be table rows.
Here is the part worth writing on a sticky note: join requests are not emailed to administrators. The only signal is a dashboard notice reading "N users pending approval". If you have ever wondered why somebody said they requested access a week ago and heard nothing, that is why. Approving is one click from either place, and the person gets an email saying their account is approved.
While they wait, they are not left guessing. Their profile shows Status: Pending Approval, the group is marked Pending in their list, and they can cancel the request themselves.
Invitations are the path of least friction
If you are setting up a team, invite people rather than asking them to sign up and wait.
The reason is mechanical. An invited user skips both steps that usually slow this down: no approval queue, and no email verification, because the invitation already proved they control the address. They click the link, choose a name and password, and land in the dashboard as a member.
The invitation email carries your logo, the inviter's name, the workspace, the role and the expiry. Links last 30 days. If the address already belongs to an existing account, there is no signup at all: a registered invitee gains access immediately, and an owner admin invitee has the role assigned on the spot.
One safeguard is worth knowing about, because it looks like a bug the first time you meet it. If someone opens an invitation link while signed in as a different person, they get Invitation not accepted rather than being added. A forwarded invite cannot quietly attach the wrong account to your organization.
Unaccepted invitations stay visible in the Users table with a Pending Invitation chip, the target role, and an Expires in N days warning once it drops under a week. Resend invitation cancels the old link and issues a fresh 30-day one, so the stale link in someone's inbox stops working the moment you send the new one.
Two things to plan around: invitations count against your plan's member allowance while they are pending, so unaccepted invites are holding seats, and only a primary admin or super admin can invite an owner admin.
Managing people once they are in
The Users table shows display name and email with inline badges, alongside roles, organization, plan, last sign-in and creation date. Search matches name or email, and the filter choices are kept in the page address, so a filtered view is bookmarkable, which is more useful than it sounds when you check the same slice every Monday.
The three-dot actions menu covers the ordinary work: edit a user's name or email, view their statistics, reset or set a password, promote someone to primary admin of a group. Checkboxes enable bulk role assignment and deletion, always skipping your own account.
Deletion offers a choice rather than one irreversible button. Permanently Delete removes the account and its data for good. Ban (Temporary Block) blocks sign-in and nothing else, and can be undone. For most of the situations that lead an admin to this menu, the reversible one is the right one, and having it there means nobody reaches for the permanent option out of a lack of alternatives. If the person is a primary admin somewhere, the confirmation spells out what happens to each of their groups before you continue.
System messages
The banners that appear on the dashboard, in chat, or in the iOS app come with a severity label: System Notice, Attention Required, or Urgent. Dismissible ones offer a dismiss link, urgent ones usually do not. Writing them is a super-admin job, so as an owner admin you are on the receiving end of these rather than the sending one.