Team & invites
How inviting someone actually works, end to end — and what they see on their side.
Sending an invite
From Members → Invite member, enter their email. Cloak does two things immediately:
1. Creates a pending invite record for that email, on this workspace
2. Sends them a real email with an "Accept invite" linkUntil they accept, they show up on the Members page with a Pending badge, and you can cancel the invite at any time.
What the invitee sees
Clicking the link takes them to sign up (Google, GitHub, or email). The important part happens automatically, right after their very first sign-in — before any workspace is created for them:
On first sign-in, Cloak checks: does a pending invite
exist for this exact email address, on any workspace?
→ Yes: they're added as a real member of that
workspace immediately. No new workspace is created.
→ No: a fresh personal workspace is created for them,
same as any other new sign-up.This is why the email address matters — someone invited at alex@company.com who signs up with a different email won't be auto-joined.
They land inside your team, not an empty dashboard
Before this, invited people would sign up and see a totally empty workspace with no sign they'd been invited anywhere. Now the moment they sign in, they're already inside the real workspace — and back on your side, their row flips from Pending to a real member automatically, live.
Member removal & token security
When an owner or admin removes a member from a workspace:
- • They receive a transactional email notification informing them of their removal.
- • All CLI machine tokens created by them in that workspace are immediately revoked.
- • Their dashboard is automatically detached from your workspace and seamlessly switched to their own personal workspace.
Roles & Plan Limits
Owner
Full control, including billing and workspace deletion. Set once, at creation.
Admin
Can manage members, invite developers, and manage secret configurations.
Member
Can view/edit secrets and environments. Cannot manage team members.
Viewer
Read-only access. Can inspect/pull secrets via CLI or dashboard, but cannot write.
Free Plan vs Team Plan
Free Plan is intended for solo developers (1 member, 3 projects, 30-day audit log). Inviting team members requires upgrading to the Team Plan ($20/mo or $240/yr).
Search, notifications, and the workspace switcher.
Dashboard