Teams, organisations and roles
Everything in SZ-MCP belongs to an organisation: the controller login, the write guard, the alert rules and notifications, the boards and the write log. To share a controller with your team, create a team organisation and invite people to it. Each member has one role, and the role decides what they can do on the dashboard and through Claude.
You manage organisations on Configure › Team (/team).
What is the difference between a personal and a team organisation?
Section titled “What is the difference between a personal and a team organisation?”Everyone gets a personal organisation at first sign-in. Only a team organisation can be shared.
| Personal organisation | Team organisation | |
|---|---|---|
| Created | Automatically, at your first sign-in | By you, under New team organisation (name up to 80 characters) |
| Members | Only you, as owner | Anyone you invite |
| Invites | Not available: the Team page shows no Invite card | Admins invite by email |
| Ownership transfer | Not possible | The owner can make another member owner |
| Deletion | Deleted with your account | The owner can delete it on the Team page |
Each organisation has its own controller login. A personal and a team organisation can point at different controllers, or at the same one with different SmartZone accounts. When you create a team organisation you become its owner, and it becomes your active organisation; then save its controller login and invite your team.
What can each role do?
Section titled “What can each role do?”Roles are ranked owner > admin > engineer > operator > viewer, and each role can do everything the roles below it can. These are the gates SZ-MCP checks on each request, on the dashboard and through Claude.
| Role | Adds these abilities |
|---|---|
| Viewer | Sees the dashboard, alerts, boards, reports and write history. Through Claude, reads everything: the controller (all reads), inventory, metrics, alerts, history, notes. Exports the configuration bundle and checks a file against the organisation (dry run). Can leave the organisation |
| Operator | Acknowledges problems and removes acknowledgements, schedules and cancels downtime. Adds and changes site notes, and saves endpoint notes. Runs synthetic checks now. Schedules a MOP that sends no writes |
| Engineer | Sends writes to the controller through Claude, under the write guard. Creates, changes and deletes alert rules; adds the starter pack; imports rules as YAML. Creates, edits and deletes boards. Runs Sync inventory and Poll now, and changes tags, locations and registered devices. Saves and runs MOPs, waives lint findings, and adds synthetic check targets. Runs the setup health report and creates the overview board. Applies a configuration bundle |
| Admin | Saves, tests and deletes the controller login. Sets up the controller tunnel and certificate (when enabled). Turns API polling and the hourly inventory refresh on or off, and manages the scrape token. Sets the write guard policy and the privacy controls. Manages notification contacts, the webhook, Jira, escalations, the heartbeat, the digest and integrations. Makes board share links. Sets branding. Invites people, changes roles and removes members. Runs the setup checklist’s privilege check and Start step, and can hide the checklist |
| Owner | Transfers ownership and deletes the organisation. There is exactly one owner |
Viewers and operators cannot send any write to the controller. Claude’s write is refused with “This person’s role in the organisation (viewer) is read-only, so this write was not sent.” Every write by an engineer, admin or owner still goes through the write guard; see Security model.
Membership and role are read on every request, never cached in a token. A role change or removal takes effect on the person’s next call, including calls from their Claude connectors.
How do I invite someone?
Section titled “How do I invite someone?”An admin invites a Google email address with a role; the person joins the next time they open the dashboard signed in with that Google account.
-
Switch to the team organisation and open Configure › Team.
-
In the Invite card, enter the person’s Email and pick a Role:
admin,engineer(the default),operatororviewer. Owner can’t be granted by invite. -
Click Invite. The card says
Invited <email>. They join the next time they open the dashboard with that Google account. -
Tell the person. SZ-MCP sends no invitation email.
The invite matches the verified email of the Google account the person signs in with, ignoring case. It lasts 14 days; pending invites are listed under Pending with their expiry and a Cancel button. Inviting someone who is already a member returns “That person is already a member.”
How do I change a role or remove someone?
Section titled “How do I change a role or remove someone?”An admin picks the new role from the member’s row, or clicks Remove.
- Role: any admin can change another member’s role to admin, engineer, operator or viewer. Your own row and the owner’s row have no role picker: another admin changes yours, and the owner’s changes only by transferring ownership.
- Remove: after “Remove <email>?” (“Their connected Claude clients stop working for this organisation at once.”) the person loses access, and their open live boards disconnect.
- Leave: any member except the owner can leave, after “Leave <name>?” (“You lose access to its controller, boards and alerts until someone invites you again.”).
How do I transfer ownership?
Section titled “How do I transfer ownership?”The owner clicks Make owner on another member’s row. After confirming “Make <email> the owner?” (“You become an admin. Only the new owner can give it back.”), that member becomes the owner and you become an admin. The owner can’t leave or be removed. To step away, transfer ownership first.
How do I switch organisations?
Section titled “How do I switch organisations?”Use the organisation menu at the top of the sidebar. It lists every organisation you belong to, with your role in each, and Team and organisations… opens the Team page. The active organisation is remembered for your sign-in session. The dashboard, and every card on it, shows the active organisation only.
A Claude connector is bound to one organisation, chosen on the consent screen when you add it. It does not follow the dashboard’s switch. To use Claude with another organisation, add the connector again and pick that one. See Connecting to Claude.