Skip to main content

Team & roles

The Team page manages the members of the workspace and pending invitations. Everyone in the workspace sees the same accounts, findings, and compliance posture.

The two roles​

AdminUser
Posture, findings, compliance, reports✓✓
Run and review scans✓✓
Connect and manage cloud accounts✓No
Invite, change roles, remove members✓No
Billing and plan changes✓No

The first user of a workspace is an admin automatically. See Sign in & activation.

Invite a member​

Admins invite by email:

  1. Enter the invitee's email, an optional name, and a role.
  2. Click Send invite. The invitee receives a Wazuh ID email to set up their account, or to use their existing one.
  3. On their first sign-in to Argus they join the workspace automatically, with the invited role. They land straight in the console, with no activation step.

Invitations expire after 14 days and can be revoked while pending from the same page.

An email address can hold one live invitation across all of Argus. Inviting someone with a pending invite from another workspace fails until that invite expires or is revoked.

note

Invitations are Wazuh-ID-based: the account created belongs to the invitee and works across the whole Wazuh Labs ecosystem, not just Argus.

Change a role or remove a member​

  • Admins switch a member's role inline from the table.
  • Removing a member revokes their workspace access only. Their Wazuh ID account is kept, and their work in the workspace, such as scans, mute rules, and connected accounts, is not deleted.

Practical patterns​

  • Keep at least two admins so a vacation never blocks an urgent credential update.
  • Most of the security team can be Users: full read access plus running scans covers day-to-day triage.
  • Revisit pending invitations occasionally. An expired invite means sending a fresh one.