Roles
Nora has three built-in roles:
Viewer (read-only) exists on Team and Enterprise plans — can see Flows and Traces but cannot edit.
Every action in the app is tied to a role check. If a button is grayed out, you’re one role short.
Inviting
Settings → Members → Invite. Fields:- Email (required).
- Role — Member by default. Owners and Managers can invite Managers and Members. Only Owners can invite Owners.
- Optional message — appears in the invitation email.
Managing an existing member
Settings → Members → click a member. Options:- Change role — up or down. Owners can be demoted only by another Owner.
- Reset session — logs the member out of every device (they’ll sign in again).
- Remove — revokes access immediately. Their content stays; their name shows in audit logs as “former member”.
The last Owner
A workspace must have at least one Owner. Attempting to remove the last Owner (or demote them) is refused with a clear error. Add a co-Owner first.Invitations that never land
If someone doesn’t receive the invitation email:- Check spam.
- Confirm the email you typed exactly matches their sign-in email.
- Resend from Settings → Members → Pending → Resend.
SSO-managed workspaces
For Enterprise workspaces with SSO enabled:- Members are provisioned via SCIM (or your IdP’s mapping).
- Local invites are disabled — the workspace roster mirrors your IdP.
- Role mapping is configured in Settings → Security → SSO.
Groups (Enterprise)
Group members into named groups:- Support team — members involved with the support Flow.
- On-call — the escalation group for approval webhooks.
- Approvers — allowed to decide approvals.
Audit
Every membership change is logged (see Audit trail):- Invites sent.
- Roles changed.
- Members removed.
- SSO provisioning events.
Removed member — what happens to their content
- Flows they authored stay.
- Datasets they authored stay.
- Feedback they submitted stays (attributed to “former member”).
- Their personal access tokens (issued via
auth login) are revoked immediately.