Your role in Docutrain decides what you can manage; a document's access level decides what you can read. The two are separate, and it helps to keep them apart.

The roles

RoleWhat they can do
VisitorNo account. Chat with public documents, open public collections and shared conversations. No dashboard.
Registered userThe above, plus what their organizations share with registered members. Manages their own profile; no admin areas.
Owner adminThe above, plus the dashboard for their organization: documents, collections, categories, branding, settings, and its users.
Primary adminOne per organization. An owner admin plus billing, and the sole right — with super admins — to invite or promote owner admins and pass the role on.
Super adminPlatform operator. Full access across every organization, plus platform-only areas such as plan management and system messages.

A person can hold different roles in different organizations: owner admin of one group, registered member of another.

Roles are assigned four ways. Signing up through Create a group makes you owner admin and primary admin of the new organization once your email is verified. An invitation carries whatever role the inviter chose — owner admins invite registered members, but only a primary admin or super admin can invite an owner admin. An approved join request always grants the registered member role. And super admins and primary admins can change a role through Edit user, though only super admins grant the super admin role. Two rules hold throughout: you cannot downgrade your own super admin role, and nobody can delete or ban their own account.

Joining and leaving groups yourself

You do not have to wait for an invitation to reach a second group, and you are not stuck in one you no longer need. Both live on your profile under Account Details, in the Owner groups panel, which super admins do not see because they already reach every group.

The header counts what you have — "2 groups · 1 pending" — and each row carries the group name, a role badge of Administrator or Member, a Primary admin marker where it applies, and Leave. Unanswered requests sit in the list marked Pending, with Cancel to withdraw.

Request access opens two tabs. Find a group searches organizations whose admins switched on Discoverable. Private group is for the rest: enter the exact Group address and choose Send request. That tab also carries Have an invite code? — a code joins you straight away, no approval needed, while a request waits for an admin to review it.

Leaving is one button and a confirmation; access goes immediately, and you can ask again later. The exception is the primary admin, whose Leave is disabled: "Transfer primary admin to someone else before leaving this group."

The Users tab

Open Users in the sidebar under Administration. Owner admins see their own organization's members and pending invitations; super admins see everyone, with extra Owner and Plan filters and row actions.

Above the list sits a Join requests section, shown only when someone is waiting. People who ask to join mid-account are not yet members, so they cannot appear as table rows; this queue is where you answer them. Each entry shows the name, email, "wants to join [group]", when they asked, and any note. Approve adds them as a registered member; Reject closes the request silently.

The table shows display name and email with inline badges — a green check for Verified, Pending for users awaiting approval, You on your own row — alongside Roles, Owner, Plan, Last Sign In and Created. Pending invitations appear as rows too, with a Pending Invitation chip, the role, the target organization, and an Expires in N days warning under seven days. Search matches email or name; filters cover Type, Role and Status, and filter choices are kept in the page address so a view can be bookmarked.

The three-dot Actions button opens User Actions: a profile summary, then Approve user where relevant, Edit user, View statistics, Reset password, Set password, Unban user, Make primary admin of [group], and — for super admins — Log in as user, Change plan and View plan history. Edit user offers Email, First Name and Last Name; super admins and primary admins also get Role and Owner Group, and a super admin editing themselves finds the selector locked.

Delete user offers a choice: Permanently Delete removes the account and its data irreversibly; Ban (Temporary Block) blocks sign-in until you unban. If the user is a primary admin, the confirmation first shows what happens to each group. Checkboxes enable bulk Assign role and Delete (N), skipping your own account.

Approving members and inviting people

Two situations put someone in front of you. A new signup created against your organization but not yet granted access shows as a Pending row. Someone who already has an account and asked to join appears in the Join requests queue instead. Either way they see nothing restricted until you approve. The dashboard shows a notice — "N users pending approval" — counting people, not requests. Join requests are not emailed to administrators, so watch that notice.

The waiting user sees Status: Pending Approval on their profile and the group marked Pending, where they can cancel; someone who signed up against your organization also gets a Pending Approval notice on the Start page.

Approving is one action — Approve user in the Actions panel, or Approve in the queue — both emailing the user "Your Docutrain account is approved".

Invite User sits at the top of the tab. Invitations count against your plan's member allowance — current members plus unexpired pending invitations — and at the limit the flow prompts you to upgrade. The form asks for an Email Address, a Role where you may choose one, and an Owner Group, read-only for ordinary owner admins.

The email, subjected "You've been invited to [organization]", shows the inviter, workspace, role, expiry and your logo. Invitations expire 30 days after being sent. The link opens a signup form with the email locked to the invited address; after choosing a name and password the account is created, verified automatically — invited users skip email confirmation — and taken to the dashboard. An invitee already signed in redeems on the spot; signed in as somebody else, they get Invitation not accepted, so a forwarded link cannot add the wrong person.

If the address already belongs to an account, no signup is needed: a registered invitee gains access at once and receives "You've been added to [organization]"; an owner admin invitee has the role assigned immediately.

Unaccepted invitations stay in the table — filter Type → Invitations — where Resend invitation cancels the old link and sends a fresh 30-day one, and Delete invitation revokes it outright.

The emails, and system messages

EventWho receives it
Invitation sentThe invited person
Invited address already has an accountThe existing user
New self-signup, and later verificationAll super admins
User approved or role grantedThe approved user
Password reset started by an adminThe user

System messages are the announcement banners that appear on the dashboard, in chat, or in the iOS app, each carrying a severity label of System Notice, Attention Required or Urgent. Dismissible ones offer a Dismiss link; urgent ones usually do not. Writing them is a super-admin job done from the System Messages tab, so as an owner admin you read these rather than write them.

Setting up a team, invitations are the path of least friction: they skip both approval and email verification.