Browse documentation

Team access & account security

Current release · Updated October 2, 2026

Invite the right people, protect administration and revoke unwanted sessions.

Invite teammates

Open Settings - Team members as owner/admin. Enter email and select member or viewer; only the owner can grant admin. Create the seven-day invitation link, copy it and share it yourself. No invitation email is sent. A replacement revokes the previous link. The recipient uses the invited email’s existing account password or creates an account and joins directly.

Pending invitations do not consume paid seats. Accepting a new member needs an available paid seat when subscribed. Viewers can read records and use lists; members can edit business data; administrators manage workspace configuration and outreach launch. Owner controls billing and administrator access. Object/field/team policies and ownership transfer are not implemented.

Change or remove access

Refresh the team before applying a role change/removal if another person edited access. Stale versions return a conflict. Owner access is protected. Removing a person invalidates their workspace sessions, revokes pending invitations sent by them and preserves business records/activity. Invitations and members paginate; expired invitations can be replaced or cancelled.

Review your sessions

Open Settings - Security for your account across all workspaces. Inspect current and other active sessions, approximate browser/OS label, sign-in time, last activity and expiry. Older sessions may have unavailable metadata. Labels do not prove a physical device or location. Activity updates roughly every five minutes; sessions last seven days. End one session, all others or the current session after confirmation.

Change your password

Enter current password, a different 10-128 character new password and confirmation. Saving rotates this session and ends every other account session. Password changes are limited to ten attempts per account per 15 minutes and disabled for the shared local sample. The private history shows the latest 20 session/password security events.

Email verification, password recovery, MFA, login OAuth, magic links, API keys and service accounts are not implemented. Native Google/Outlook connection grants mailbox access for outreach; it is not account sign-in. For access problems contact support@drykraft.com without sharing passwords or session cookies.