Team and Access Management
Runless team access is managed inside the product tenant. You do not need to administer a separate customer-side Cognito user pool.
Roles
| Role | Permissions |
|---|---|
| Owner | Invite/remove members, manage AWS connections, configure runtime rules |
| Member | Operate dashboard workflows allowed by tenant policy |
Invite a Team Member
2
- Sign in to Runless.
- Open the dashboard and go to Team.
4
- Enter user email.
- Choose role (
OwnerorMember). - Click Send invite.
6
- Invitee receives an email invitation.
- After acceptance, member appears as Active in Team list.
Remove a Team Member
- Open Team list.
- Find the member.
- Click Remove and confirm.
Runless prevents removing the last owner of a tenant. Assign another owner first if you need to transfer ownership.
Seat Limits
If your plan seat limit is reached, new invites are blocked until you:
- Remove existing members, or
- Upgrade your plan limits
Access Best Practices
- Keep at least two owners for operational continuity
- Grant owner role only to users managing account linking or governance
- Review team membership regularly
Troubleshooting
Invite not received
- Ask the user to check spam/junk folders
- Verify email address in invite form
- Re-send invite from Team tab
Member cannot access linked account actions
- Verify member role and tenant membership
- Confirm the linked AWS connection status is verified and commercially active
Next Steps
- Application Manual - Use runtime controls and schedules
- Account Unlink & Offboarding - Remove accounts safely when needed
