---
title: "Change roles and remove members"
description: "How to work the IoTFlows member directory at /members: one search field covering teams and members, the row controls that change a role and remove someone, and what removal leaves behind. Changing a role opens the Edit member role dialog and reports \"Member role changed to\" the new role. Removing opens the Remove member dialog, and if the person is the last administrator of something inside the organization, a second step asks whether to keep or delete what they administer. A removed member loses access to everything, and their open work orders stay open and become unassigned. The dashboard has no dedicated transfer-ownership control: ownership moves by setting another member's role to Organization Owner."
category: "People and access"
source_url: "https://www.iotflows.com/docs/admin/manage-members/"
---
# Change roles and remove members

Change what someone can do, take their access away, or hand the organization to someone else.

**Prerequisite** Organization Owner or Organization Administrator. See [Roles and permissions](/docs/admin/roles-reference/#roles). Ownership transfer is Owner only.

The *directory* is the member list at `/members`. It carries every person in the organization and every team, and it is where roles change and memberships end. Adding people is a separate task, see [Invite people to your organization](/docs/admin/invite-members/).

## 1. The directory
Open **Members** at `/members`. The page holds two panels: **Teams** above, **Members** below.

The Teams panel is a table with three columns, **Name**, **Handle**, and **Members**. Selecting a team opens it, see [Create and manage teams](/docs/admin/teams/).

The Members panel is one row per person. Each row shows an avatar, the person's name, their public username in italics, and their organization role beneath.

A row for an invite nobody has accepted yet reads differently: the invited email address in italics, followed in amber by `[Invite sent. Pending account creation]`, and no role line. See [Pending invites](/docs/admin/invite-members/#pending).

Three controls sit at the right of every member row.

![The Members page at /members. A search field across the top reads Search teams and members or invite via email. Below it a Teams panel lists three teams in a table with Name, Handle, and Members columns and a Create Team control. Beneath that a Members panel lists twelve rows, each carrying an avatar, an organization role, a machine-access chip, a pencil, and a trash icon. Ten rows show a name and a public username; two show an email address followed by an amber note reading Invite sent. Pending account creation](/images/admin/adm-members-01.webp)

*The directory searches teams and members together.*

### Row actions
| Action | Who can | Reversible | Effect |
|---|---|---|---|
| Machine access chip, reading **All machines** or showing the machines they are scoped to | Owner or Administrator. The chip does not render for anyone else | Yes | Opens the machine-access dialog for that person. See [Limit which machines a member can see](/docs/admin/machine-access/) |
| Pencil | Owner or Administrator | Yes, change the role again | Opens **Edit member role**. See [Change someone's role](#role) |
| Trash | Owner or Administrator | No, you re-invite and get a new membership | Opens **Remove member**. On a pending row this cancels the invite. See [Remove a member](#remove) |

> **Info:**
> **Why can I see these controls without an admin role?**
>
> The machine-access chip is the only row control the dashboard hides from non-admins. The pencil and the trash render for every signed-in member, and IoTFlows enforces the role when the request reaches the platform. Treat the [permission matrix](/docs/admin/roles-reference/#matrix) as the rule, not the controls you happen to see.

## 2. Search members and teams
One field at the top of the page filters both panels at once. It reads `Search teams and members or invite via email`.

Type any part of a first name, last name, public username, or email address to filter the Members panel. Type any part of a team name or team handle to filter the Teams panel. Searching `line 2` narrows both: teams whose name contains it, and nobody in the member list unless a name matches.

Matching members appear under the heading **In this organization**. When nothing matches, the panel reads `No members match "line 2"` or `No teams match "line 2"`.

The search covers this organization only. To find someone who already uses IoTFlows but is not a member yet, open **Add Member** and search there instead, see [Add an existing user](/docs/admin/invite-members/#existing).

## 3. Change someone's role
1. Open **Members** at `/members`.
2. Find the person, using the [search field](#search) if the list is long.
3. Select the pencil at the right of their row.
4. Under **Organization Roles**, select a role. Hovering a role name shows its description.
5. Select **Edit role**.

The dialog closes and a message reads "Member role changed to Organization Administrator", naming the role you picked. The new role applies immediately: the person does not sign out and back in.

IoTFlows serves the role list, so the options in this dialog come from the platform rather than from your organization. What each one can do is in [Roles and permissions](/docs/admin/roles-reference/#matrix).

![The Edit member role dialog, showing one member's avatar, public username, and email at the top. A violet highlight surrounds the radio list headed Organization Roles, with Organization Owner, Organization Administrator, Organization Member, and Organization Observer, and Organization Administrator selected. Cancel and Edit role sit at the bottom](/images/admin/adm-members-02.webp)

*Changing a role. Change the role rather than removing and re-inviting.*

Change a role rather than removing someone and re-inviting them. Re-inviting creates a new membership, and everything tied to the old one, work orders, board memberships, machine access, and chat history, has to be rebuilt by hand. Changing the role keeps the membership and swaps only what it can do.

Choose a role change over a removal whenever the person stays on site. A supervisor who now adds machines moves from Member to Administrator. A seasonal contractor who should read reports and change nothing moves to Observer. An operator who cannot classify downtime is almost certainly an Observer, see [Which role for an operator?](/docs/admin/roles-reference/#roles)

## 4. Remove a member
Removal ends the membership. Do the two things below first, because neither is recoverable from the directory afterwards.

> **Warning:**
> **Before you remove anyone**
>
> Reassign their open work orders. Removal leaves those work orders open and unassigned, and an unassigned work order is one nobody is watching.
>
> Reassign from the work order itself, see [Update, discuss, and close a work order](/docs/maintain/work-order-detail/). Then check whether they own anything only they administer, which the dialog asks about in step 5 below.

1. Open **Members** at `/members`.
2. Find the person.
3. Select the trash at the right of their row.
4. In the **Remove member** dialog, check the name, username, and email against the person you meant. Select **Confirm remove**.
5. If a second step appears, answer it. See [If they are the last administrator](#last-admin).

A message reads "Member has been removed" and the row leaves the directory.

![The Remove member dialog, headed Remove member, showing one member's avatar, full name, public username, and email address. Cancel sits at the bottom left and Confirm remove at the bottom right](/images/admin/adm-members-03.webp)

*Removing a member.*

On a row that still reads `[Invite sent. Pending account creation]`, this same dialog is how you cancel the invite. The wording does not change, so the dialog says "Remove member" and reports "Member has been removed" about an address that never accepted.

### If they are the last administrator
If the person is the only administrator of something inside the organization, **Confirm remove** does not finish. The dialog swaps to a second step reading `Maria Lopez is the last administrator of at least one resource in this organization.` and asks **Would you like to:** with two options.

| Option | What it does | Choose it when |
|---|---|---|
| **Keep resources and remove member** | Removes the membership and leaves everything they administered in place | Almost always. The resources stay, and you give someone else administrative access to them afterwards |
| **Delete all resources and member** | Removes the membership and deletes everything they were the last administrator of | You are cleaning up a test membership, or you have confirmed nobody relies on those resources |

Select one, then select **Confirm**. The message is the same, "Member has been removed".

Default to **Keep resources and remove member**. Deleting is not reversible from this dialog, and the dialog does not list what it is about to delete. Something nobody noticed this person administered is how a plant loses a setting it was relying on.

## 5. Transfer ownership
The *Owner* is the role that pays for IoTFlows and the only one that can hand the organization over. Every organization has at least one, see [Owner-only actions](/docs/admin/roles-reference/#owner-only).

The dashboard has no button labelled Transfer ownership. Ownership moves through the role dialog: the current Owner gives another member the **Organization Owner** role, using the steps in [Change someone's role](#role), and then takes **Organization Administrator** for themselves. An Administrator has the same authority minus billing, so the person handing over loses nothing else.

![The Edit member role dialog for a second member, showing their avatar, name, public username, and email. A violet highlight surrounds Organization Owner at the top of the Organization Roles radio list, and its radio is selected](/images/admin/adm-members-04.webp)

*Transferring ownership. An Owner cannot leave without doing this first.*

Transfer ownership before the current Owner's last day, not after. An Owner cannot leave the organization while they are the only Owner, and an organization whose Owner has gone cannot pay an invoice or clear a suspension. If that has already happened, [contact IoTFlows](/docs/get-started/get-support/).

## 6. What removal does
Removal is total. The person loses the organization everywhere it appears: the web dashboard, the mobile app, every board, every team, and every chat inside it. They keep their IoTFlows account and any other organization they belong to, see [Switch organizations](/docs/get-started/switch-organizations/).

What the organization keeps:

- **Their work orders stay open and become unassigned.** The work is not deleted and not closed. Nobody owns it, and nothing in the product flags it, which is why reassigning before removal matters.
- **Their history stays.** Downtime they classified, jobs they ran, and comments they wrote are still attributed to them.
- **Whatever they administered stays**, unless you chose **Delete all resources and member** at [the last-administrator step](#last-admin).
- **The removal is recorded.** See [Review the organization audit log](/docs/admin/audit-log/).

What does not come back:

- **Machine access.** A membership you re-create starts with access to all machines, and any [restriction](/docs/admin/machine-access/) you had set is gone.
- **Team membership and board membership.** Re-add them by hand.
- **The membership itself.** Re-inviting creates a new one, which is the whole reason to change a role instead.

> **Info:**
> **Someone says a machine disappeared**
>
> That is usually a machine-access change rather than a removal, because a restricted member keeps their sign-in and only loses the machines. See [Limit which machines a member can see](/docs/admin/machine-access/).

## See also
- [Roles and permissions](/docs/admin/roles-reference/)
- [Limit which machines a member can see](/docs/admin/machine-access/)
- [Create and manage teams](/docs/admin/teams/)
- [Invite people to your organization](/docs/admin/invite-members/)
- [Review the organization audit log](/docs/admin/audit-log/)
