Team
Give people access to the correct merchant and review that access as responsibilities change.
On this page
Sign-in and membership
Carden uses WorkOS AuthKit for sign-in. Authentication establishes who someone is; merchant membership and permissions determine what they may see or change. Access to /dashboard is merchant-scoped. Carden operator access to /admin is a separate privilege, not a merchant team role.
The same person may have access to more than one organization. Confirm the active merchant before inviting anyone or changing a role. A QuickBooks connection invitation authorizes a provider connection; it is not automatically an invitation to the Carden team.
Invite a teammate
- Open Team for the intended merchant with an account allowed to manage members.
- Enter the teammate's work email and choose the least-privileged role appropriate for their responsibilities.
- Review the permissions attached to that role or membership before sending the invitation.
- Ask the recipient to complete the AuthKit sign-in flow with the invited identity.
- Check that the membership is active and the person can access the intended merchant, without giving them an operator account.
If an invitation expires or the email is incorrect, revoke or replace it through your team's management workflow. Avoid creating shared logins to bypass invitation problems.
Review and remove access
- Review owner and administrative access regularly and after personnel changes.
- Keep at least one active, accountable owner before transferring ownership or removing a member.
- Remove access when responsibilities end, and review any API keys or webhook destinations that person managed.
- Rotate service secrets separately when exposure is possible; removing a human membership should not be treated as proof that every machine credential was revoked.
Resolve missing access
Have an owner verify the invited email, merchant, invitation status, and assigned role. Sign out and sign in with the intended identity if the browser is using another account. If permission is still missing, collect the operation and request ID rather than attempting the action with another merchant's credentials.