Work with teammates
Invite people to your organization so they can deploy too, or let everyone at your email domain join themselves — how roles work today, and what belonging to several organizations means.
Your organization is your account. Everything you make belongs to it, and anyone you invite works on the same things you do, from their own agent.
Ask for it
invite sam@company.com to my agenthost account
Sam gets no password and no key. They point their own MCP client at agenthost, sign in with that email address, and land in your organization. If Sam already uses agenthost for something else, they keep their own account and gain yours alongside it — the next time they sign in, they're asked which one the connection is for.
Roles
Everyone has a role: owner, admin or member. Ask for one explicitly if it matters:
invite sam@company.com as an admin
| Role | Today |
|---|---|
owner | Everything, including inviting people |
admin | Everything, including inviting people |
member | Everything except inviting people |
Roles are barely a boundary right now
Only inviting users is role-gated. A member can create, deploy, and delete any app or project
in the organization. Treat an invitation as full trust, and use
app-level invitations for anyone who should merely see something.
Let your whole team in at once
If everyone who should be here has an email address at the same domain, claim it and stop inviting people one at a time:
everyone at acme.com should be able to use our agenthost account
From then on, anyone with an @acme.com address who signs in to agenthost for the first time is
shown your organization and joins it as a member — no invitation, no waiting for you.
You can claim more than one:
our people are on acme.com and acme.co.uk
What it does and doesn't do
- It only affects people who are new to agenthost. Someone who already has an agenthost account keeps it. Claiming a domain never reaches back and collects existing users, whoever they work for.
- They are offered it, not forced into it. The sign-in page names your organization and the domain it matched, and offers "create my own organization instead" right beside it.
- They accept the terms for themselves. Joining records their own acceptance, with the versions they were shown. Your organization's agreement — made when it was created — is untouched: nobody joining re-signs it on your behalf.
- They arrive as
member— the least-privileged role. Promote anyone who needs more. - Each one takes a seat, and seats are unlimited on the paid plan. This is a paid feature: on the free plan, which is one person, there's no team to join.
- Removing a domain removes nobody. It stops future signups; everyone already in stays in.
Claiming and unclaiming
Ask your agent to show the list before changing it — the tool replaces it rather than adding to it:
which email domains join our agenthost account?
stop taking new people from acme.co.uk
A claimed domain is an open door
Anyone who can get an address at that domain can walk into your account and see everything in it.
That's the right trade for a company domain where IT controls the addresses. It is the wrong trade
for a domain where anyone can sign up for a mailbox — and public providers like gmail.com are
refused outright for that reason. A domain can only belong to one agenthost account; if yours is
already taken, write to us.
Seeing who's in
who has access to my agenthost account?
You get everyone and the role they hold here. People who also work for other organizations keep that private — you only see their role on yours.
Belonging to more than one
This is the normal case for an agency or a freelancer: your own organization, plus one per client.
- A connection belongs to one organization. Your agent acts inside it and can't see the others.
- To work on a different one, connect your MCP client again and pick that organization when signing in. There's no tool that switches mid-conversation.
whoamilists the other organizations the same person belongs to, so your agent can tell you which one it's currently in — worth asking before a destructive request.
which agenthost organization am I connected to right now?
Removing someone
There is no tool for removing a person from an organization yet. If you need someone taken off, contact us — and in the meantime, revoke anything they hold: API tokens they minted can be revoked by id, and app invitations can be revoked individually.
Under the hood
Access is a membership: a row joining one person to one organization with one role. Every authenticated request re-checks it, so a change takes effect immediately rather than at the next sign-in. Every credential agenthost issues — OAuth grant, API token, browser session — is bound to exactly one organization, and every tool call is scoped to it.
A claimed email domain is checked at one moment only: when an address agenthost has never seen finishes proving it owns that address. The plan is re-checked at the same moment, so if an account lapses to the free plan its domains stop admitting anyone that instant, and start again if it re-subscribes — there's no list to remember to clear.