> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Managing enterprise workspace members and groups

> Organize members into groups, control member roles, set per-member credit limits, and manage who can invite external collaborators in your enterprise workspace.

Enterprise workspaces include additional controls for managing your team at scale. You can assign the Admin role to trusted members, organize members into groups that grant a shared role, cap how many credits individual members can use each month, and control who can invite external collaborators to your apps.

For general member management, including inviting members, updating roles, and removing members, see [Managing workspace members](/Account-and-billing/Managing-your-workspaces).

<Frame caption="The Members tab in Members and groups">
  <img src="https://mintcdn.com/base44/178rQscgG2UynUrG/images/members-and-groups.png?fit=max&auto=format&n=178rQscgG2UynUrG&q=85&s=f81d1f85373e9a5f383bec0e8f37f65a" alt="The Members tab in Members and groups showing workspace members, roles, credit usage, apps, and Superagents" width="2630" height="1608" data-path="images/members-and-groups.png" />
</Frame>

***

## Workspace roles

Enterprise workspaces include an additional **Admin** role alongside the standard Owner, Editor, and Viewer roles.

| Role       | What they can do                                                                                             |
| ---------- | ------------------------------------------------------------------------------------------------------------ |
| **Owner**  | Manages billing, members, settings, apps, and credits. Each workspace has one owner.                         |
| **Admin**  | Manages members and workspace settings, but does not handle billing. Enterprise plan only.                   |
| **Editor** | Builds and edits apps, uses credits from the workspace pool, and has read-only access to the **Groups** tab. |
| **Viewer** | Has read-only access to specific apps and does not consume credits.                                          |

<Note>
  If a workspace downgrades from the Enterprise plan, any members with the Admin role are automatically moved to the Editor role.
</Note>

***

## Managing workspace groups

Workspace Owners and Admins can assign one workspace role to multiple members at once by creating a group. When a group has a role, its members inherit that role, so you can manage access by team instead of one person at a time. If someone belongs to more than one group, they get the highest role among their groups.

Once a group exists, you can use it across Base44:

* **Workspace roles:** Assign a role to the group so its members inherit it, as described in this section.
* **App access:** [Give a group access to a specific app](/Setting-up-your-app/Managing-access#giving-a-group-access-to-your-app) with one role, kept in sync as people join or leave.
* **Publishing permissions:** [Set publishing permissions for a group](/Enterprise/Enterprise-SSO-and-app-visibility#setting-publishing-permissions-for-groups) that its members follow instead of their role's.

Groups are on the **Groups** tab of the **Members and groups** page. There are two types: **Custom** groups that you create and manage in Base44, and identity-provider (IdP) groups synced from your identity provider.

<Frame caption="The Groups tab in Members and groups">
  <img src="https://mintcdn.com/base44/178rQscgG2UynUrG/images/workspace-groups-tab.png?fit=max&auto=format&n=178rQscgG2UynUrG&q=85&s=686d127d50ca67d6f9681055635f2202" alt="The Groups tab showing identity-provider groups and the option to add a custom group" width="2016" height="1136" data-path="images/workspace-groups-tab.png" />
</Frame>

<Note>
  **Good to know about groups:**

  * If a member inherits their role from a group, you cannot change it from the member row on the **Members** tab. Change the group's role or the member's group membership instead.
  * Editors can open the **Groups** tab in read-only mode. They see the group list, each group's role, and its members.
</Note>

### Creating a custom group

Custom groups are created and managed in Base44 and don't require SSO or SCIM.

1. Open **Settings** → **Members and groups**, then select the **Groups** tab.
2. Click **Add custom group**.
3. Enter a **Group name**.
4. Add a **Group description (optional)**.
5. Choose the **Role** every member inherits: **Admins**, **Editors**, or **Viewers**. To create the group without granting a role, choose **No assigned role**. The group does not grant a role.
6. (Optional) Add members to the group.
7. Click **Create group**.

### Managing a group

To view or edit a group, click the **More Actions** <Icon icon="ellipsis" /> icon next to it and select **View group**. In the **View group** dialog you can rename the group, change the **Role** it grants, or add and remove members. Click **Save** to apply your changes.

To delete a group, click the **More Actions** <Icon icon="ellipsis" /> icon next to it and select **Delete group**.

Deleting a group does not remove its members from the workspace. Their roles are recalculated from remaining groups or the workspace default.

### Working with identity-provider groups

Identity-provider (IdP) groups are synced into Base44 from your identity provider through SCIM and appear with the **IDP** badge. Their name and membership come from your identity provider, so they're read-only in Base44. You assign the workspace role each IdP group grants.

To let IdP groups govern member roles, turn on **Use identity-provider groups** in the **Identity-provider groups** section of the **Groups** tab. SSO must be set up first. IdP groups require a custom Enterprise plan with SCIM configured. To set up syncing, see [SCIM provisioning](/Enterprise/SCIM-provisioning).

***

## Credit limits

You can control how many credits workspace members can use per month. There are two levels: a workspace default that applies to everyone, and individual overrides for specific members.

Credit limits apply to the Admin and Editor roles only. Viewers do not consume credits, so a credit limit cannot be set on a Viewer.

### Default credit limit

The default credit limit sets a monthly cap that applies to all workspace members automatically. If you also set a limit on a specific member, that individual limit takes priority over the default.

**To set a default credit limit:**

1. Click your workspace name at the bottom left.
2. Click **Settings**.
3. Click **Members and groups**.
4. Click the **More Actions** <Icon icon="ellipsis" /> icon at the top right of the members list.
5. Click **Set default credit limit**, enter the limit, and click **Set credit limit**.

To remove the default limit, open the same dialog and click **Clear limit**.

<Frame caption="Setting the default credit limit">
  <img src="https://mintcdn.com/base44/178rQscgG2UynUrG/images/defaultcreditlimit.png?fit=max&auto=format&n=178rQscgG2UynUrG&q=85&s=e90c85a7856386438f7b5620ca1463e3" alt="The Set default credit limit option on the Members tab in Members and groups" width="2676" height="1086" data-path="images/defaultcreditlimit.png" />
</Frame>

### Per-member credit limits

You can set a credit limit for a specific member to override the workspace default.

**To set a credit limit for a member:**

1. Click your workspace name at the bottom left.
2. Click **Settings**.
3. Click **Members and groups**.
4. Click the **More Actions** <Icon icon="ellipsis" /> icon next to the relevant member.
5. Click **Set credit limit**, enter the limit, and click **Save**.

<Frame caption="Setting a member's credit limit">
  <img src="https://mintcdn.com/base44/178rQscgG2UynUrG/images/creditlimit.jpg?fit=max&auto=format&n=178rQscgG2UynUrG&q=85&s=625d286e6248b23090016b05d0361a78" alt="The Set credit limit option for a member on the Members tab in Members and groups" width="2092" height="1192" data-path="images/creditlimit.jpg" />
</Frame>

You can also set credit limits automatically when provisioning users through SCIM. See [SCIM provisioning](/Enterprise/SCIM-provisioning#per-member-credit-limits).

***

## External collaborators

You can restrict who is allowed to invite external guests to your apps. See [Controlling guest invitations](/Account-and-billing/Managing-your-workspaces#controlling-guest-invitations).
