> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.alpha.openantares.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.alpha.openantares.com/_mcp/server.

# People and access

Alpha has two access layers. The organization determines who belongs to the workspace. Each vault determines who may open a specific client, project, or internal workspace.

## Organization roles

| Role    | Organization capabilities                                 | Vault access                                   |
| ------- | --------------------------------------------------------- | ---------------------------------------------- |
| User    | Use Alpha, browse the vault directory, and request access | Only vaults where they are a member or manager |
| Manager | Create vaults and use organization features               | Only vaults where they are a member or manager |
| Admin   | Manage organization settings, people, and limits          | Every vault in the organization                |

The platform also has a system administrator role for operating Alpha itself. It is not a role that organization admins assign from this screen.

## Vault roles

| Role          | Capabilities inside that vault                                    |
| ------------- | ----------------------------------------------------------------- |
| Member        | Read vault knowledge and use permitted product features           |
| Vault manager | Manage members, routing, sources, review work, and vault settings |

An organization Manager is not automatically a manager of every vault. Add them to the specific vaults they should manage.

## Invite a person

Invite someone from **Settings > Members & access**. They receive an email and join with the organization role you select. Grant vault access separately unless they are an organization admin.

An invited person sees existing vaults they can use during onboarding. They can connect their own accounts and send approved work directly into those vaults instead of creating duplicate client workspaces.

## Personal routing additions

Keywords and domains added by a regular member apply to source material from that member's connected accounts. They can add terms without removing rules created by another person.

A vault manager can review member additions in the vault settings and promote selected rules so they apply to everyone feeding that vault.

## Access requests

If a person sees a vault they cannot open, they can request access. Every vault admin receives an in-app notification and email. The approver chooses the person's vault role and can add them to other relevant vaults at the same time.

The requester receives an in-app notification when the request is approved or denied.

## Notifications

The Inbox in the left navigation collects access requests, approvals, agent updates, task reminders, and ingestion issues. Use it as the shared place for work that needs a human decision.

## Removal and revocation

* Removing a vault membership revokes access only to that vault.
* Removing an organization membership revokes access to the organization and its vaults.
* Revoking a membership immediately reduces what the person's OAuth sessions, API keys, and MCP clients may reach.
* Previously imported source material remains in its vault unless a vault manager deletes it separately.

See [Organization settings](/organization-settings) for the controls and [Data boundaries](/data-boundaries) for the underlying scope model.