Skip to documentation content

Team

Give each person access to the intended merchant workspace and remove it when responsibilities change.

On this page

Sign-in and membership

WorkOS AuthKit identifies the person signing in. Carden membership determines which merchant they can access and what they can change. A person can belong to multiple organizations, so confirm the active merchant before any action.

A QuickBooks connection invitation authorizes an accounting connection. It does not add the recipient to the Carden team or grant payment-provider access.

Invite a teammate

  1. Open Team in the intended merchant workspace.
  2. Enter the person's work email and select the least-privileged suitable role.
  3. Send the invitation and have the recipient sign in with that identity.
  4. Confirm active membership is limited to the intended merchant.

Review and remove access

  • Review owner and administrative access after personnel changes.
  • Keep at least one accountable owner active.
  • Remove memberships when access is no longer needed.
  • Review service keys and webhook destinations separately; removing a person does not revoke machine credentials.

Resolve missing access

Have an owner check the invited email, organization, invitation state, and role. If the browser uses another identity, sign out and return with the invited account.