Skip to main content
Team & Access

Managing members: tools, roles, suspension, and reactivation

The Active Members list on the Team page is your day-to-day roster. From it you change what each member's AI assistant can do, promote or demote roles, and suspend or restore access. This page covers…

Written By Christopher Scaminaci

Last updated 3 days ago

The Active Members list on the Team page is your day-to-day roster. From it you change what each member's AI assistant can do, promote or demote roles, and suspend or restore access. This page covers each action and — importantly — exactly what stops working when you revoke someone.

Reading the members list

Each row shows: name, role badge (Owner / Administrator / Member), an Active or Deactivated badge, a name chip for each custom role the person holds, email, join date, a tool label, and — once the person's agents have made any — a tool-call count.

The tool label depends on whether they hold a custom role. For someone with no role it reads "All tools" or "N tools". Once they hold one it starts with "Role tools" — shown as "Role tools + N tools" whenever their own extra-tool list is recorded, which is why a role-holder with no extras of their own reads "Role tools + 0 tools".

The Active Members card showing one owner row with active status, tool scope, usage, and connection counts
A populated member row with the person's name and email replaced by fictitious examples. Expand the chevron to see that member's connection-management controls.

Change a member's tools (Edit Tools)

Who can do it: Owner, Co-owner, or Administrator. The tools button appears on Member and Administrator rows — owners never show it, because they can't be restricted through their member record.

  1. On the member's row, select Edit Tools (or Edit Extras — see below).
  2. Adjust the selection — the picker offers All Tools, Read Only, Write and Clear buttons, a search box that ranks results by relevance, and a chip per connector for narrowing the list, with bulk actions that apply to just what's currently shown.
  3. Select Save.

The change applies to the member and to every AI-assistant credential they own — their agents pick up the new tool set on the next request, without reconnecting.

How a full selection is stored depends on the person:

  • For someone who holds no custom role, selecting the whole offered catalog saves as "All tools" (unrestricted) — but only when the automation tools are part of what's offered to you; otherwise it saves as the explicit list you ticked.
  • For a role-holder the save is always an explicit list, never the unrestricted setting. Ticking everything therefore grants exactly the tools on screen today, and nothing added later.
  • If you open the dialog on an unrestricted member and save without changing anything, StackJack deliberately writes nothing and says so: "No permission changes to save —

The dialog header always reads Edit Tools — , even when the button on the row said Edit Extras. If StackJack can't read your custom roles it shows a Roles unavailable warning with a Retry, and Save stays disabled until they load — the picker can't be trusted to show what the person holds until then.

If you are picking the same tools for person after person, assign a custom role instead — a reusable bundle whose rules pick up new tools automatically. Two practical notes:

  • Edit Roles is on every active Member and Administrator row, whether or not the person holds a role yet, and it works on an account with no connector connected. The tools button beside it needs at least one available connector before it appears.
  • To stop assigning roles by hand, Directory sync grants and removes them from Microsoft Entra group membership. A role it granted is badged "via directory sync" and is changed in the mapping rather than on the member.

Large tool selections and client limits. Above 70 selected tools the picker shows a Large tool selection warning, because several MCP clients cap how many tools a server may expose and the caps differ per client. The maintained list is Client tool limits — check it rather than a number quoted elsewhere. The fix is the compact catalog: a client that cannot carry a query string uses the compact endpoint address instead (compact.stackjack.io/mcp in the US; copy your own from MCP Setup), which serves the short list with nothing to enable first. Some clients can instead append ?tools=compact to their standard MCP URL — for that route, enable catalog modes on the Settings page first, or pin a smaller tool set.

Member credentials follow the member's tools

When a member completes one of their own personal connector sign-ins on Connectors (/connectors), StackJack auto-mints a personal Client ID + Secret for them. Those per-member credentials appear when you expand that member's row in the Active Members list — under Member credentials, alongside their connected apps and AI sessions — where a manager can Rotate Secret or Revoke their credentials and connected apps (their AI sessions are listed read-only). Their tools are not set there — they follow the member's own tools: the roles you assign with Edit Roles plus the tools you pick with Edit Tools. Saving Edit Tools, changing the member's roles, and editing or deleting a role they hold each update all of that member's credentials at once. The member's own next sign-in to a connector updates the credential linked to that connection. A co-owner's credentials carry every tool, unless the credential itself holds a role. Full detail: Managing MCP client credentials and API keys.

Change a member's role

Who can do it: Owner or Co-owner only.

  • Make Administrator — grants full operational management (everything except billing and ownership; see the capability matrix).
  • Demote to Member — returns an Administrator to a plain member.
  • Switching between Member and Administrator leaves the person's tool assignment untouched — adjust it separately with Edit Tools if needed.
  • Make Co-owner — full account control; a strong confirmation dialog spells out the consequences before you commit. Promotion removes the member-level tool restriction, so their portal sign-in and any unscoped AI-assistant credential resolve to every tool — but a credential of theirs that carries custom roles of its own keeps serving only those roles' tools.
  • Remove Co-owner — see Ownership and transfer. The demoted person ends up with no tools assigned until you set some — unless they hold a custom role, which demotion leaves in place: then they land on exactly that role's tools and keep working normally. Roles are removed with Edit Roles, not Edit Tools.

Suspend a member (Revoke Access)

"Revoke Access" is StackJack's suspension: the person stays in the list with a Deactivated badge, but every way they could reach your data stops working.

  1. On the member's row, select Revoke Access.
  2. Confirm the dialog — it warns that their MCP credentials stop working immediately.

What is shut off, all in one step, effective on the person's next request:

Access pathEffect
Portal sign-inThey see an "Access Revoked" notice instead of your data
Their MCP clients / API keysDeactivated
Their per-user connector credentialsDisabled
"Sign in with StackJack" OAuth registrationsRevoked
Connected-app (shared AI app) authorizationsRevoked

Guardrails: Revoke Access appears only on Member and Administrator rows — an owner can never be suspended directly. To suspend a co-owner, remove their co-owner status first (Ownership and transfer); the Primary Owner can only ever leave via an ownership transfer, and StackJack refuses any action that would strip the account's last owner.

Restore a member (Reactivate)

On a deactivated row, select Reactivate and confirm. The member comes back with the same tool assignment they had before the suspension (change it afterward with Edit Tools if needed). Restoration is precise:

  • Their membership comes back, along with the AI-assistant credentials (manual Client ID/Secret and API keys) that the suspension itself switched off. Credentials revoked separately — for cause by you or by StackJack support, and any that were switched off before StackJack began recording why — are not reinstated and have to be re-issued.
  • Their per-user connector credentials are re-enabled — unless a credential was disabled for a separate reason (for example a failed connector validation), in which case that credential stays disabled until fixed.
  • Connected-app authorizations that were revoked by the suspension itself are reinstated; anything you or StackJack support revoked separately stays revoked.
  • "Sign in with StackJack" registrations are not restored. Any AI tool the person had connected via browser sign-in must sign in again — the tool re-registers automatically the first time it reconnects, so this is a one-time re-login, not a setup redo.

If your organization runs Directory sync: a manual Reactivate will not stick for someone whose Microsoft Entra account is disabled while they are still in a mapped group — the next sync run deactivates them again; re-enable the account in Entra instead. That applies however the member joined. Someone the sync deactivated because they left every mapped group stays reactivated once you reactivate them by hand — the sync does not re-deactivate a row it already settled. And a Revoke Access you performed by hand is left alone entirely: if that person matches a mapping again, the sync flags them for review rather than reactivating them.

Unlinked Identity Users

At the bottom of the Team page, the Unlinked Identity Users card lists people who exist in your identity organization but aren't StackJack team members (and have no pending invite). The card only appears when at least one such user exists. For each:

  • Resend Setup Email — shown only for users still in "Pending Setup" who never finished choosing a password.
  • Add to Team — makes them a member immediately, with an optional tool restriction. They're notified by email.

If a member's identity was deleted and re-created

If someone's sign-in identity is removed and later re-created with the same email (for example after an identity cleanup), StackJack can re-link their membership, MCP clients, and connector credentials to the new identity at their next sign-in. Usually no admin action is needed.

Two conditions have to hold, and both exist to stop somebody claiming another person's account by setting the same address:

  • The new identity's email must be verified. An unverified address is refused, and the person is treated as a new sign-in with nothing inherited. If they are stuck in that state, have them finish email verification, then sign in again.
  • A suspended member is not re-linked back into access on its own. If the matching member row is deactivated, the sign-in is refused unless there is an active grant for them — a pending invite, or an admin granting them access. Reactivate them on the Team page, or send an invite, and the relink completes on their next sign-in.

If something looks duplicated afterward, contact support@stackjack.io.