Skip to content
SZ-MCP
Get Support

Teams, organisations and roles

Everything in SZ-MCP belongs to an organisation: the controller login, the write guard, the alert rules and notifications, the boards and the write log. To share a controller with your team, create a team organisation and invite people to it. Each member has one role, and the role decides what they can do on the dashboard and through Claude.

You manage organisations on Configure › Team (/team).

What is the difference between a personal and a team organisation?

Section titled “What is the difference between a personal and a team organisation?”

Everyone gets a personal organisation at first sign-in. Only a team organisation can be shared.

Personal organisationTeam organisation
CreatedAutomatically, at your first sign-inBy you, under New team organisation (name up to 80 characters)
MembersOnly you, as ownerAnyone you invite
InvitesNot available: the Team page shows no Invite cardAdmins invite by email
Ownership transferNot possibleThe owner can make another member owner
DeletionDeleted with your accountThe owner can delete it on the Team page

Each organisation has its own controller login. A personal and a team organisation can point at different controllers, or at the same one with different SmartZone accounts. When you create a team organisation you become its owner, and it becomes your active organisation; then save its controller login and invite your team.

Roles are ranked owner > admin > engineer > operator > viewer, and each role can do everything the roles below it can. These are the gates SZ-MCP checks on each request, on the dashboard and through Claude.

RoleAdds these abilities
ViewerSees the dashboard, alerts, boards, reports and write history. Through Claude, reads everything: the controller (all reads), inventory, metrics, alerts, history, notes. Exports the configuration bundle and checks a file against the organisation (dry run). Can leave the organisation
OperatorAcknowledges problems and removes acknowledgements, schedules and cancels downtime. Adds and changes site notes, and saves endpoint notes. Runs synthetic checks now. Schedules a MOP that sends no writes
EngineerSends writes to the controller through Claude, under the write guard. Creates, changes and deletes alert rules; adds the starter pack; imports rules as YAML. Creates, edits and deletes boards. Runs Sync inventory and Poll now, and changes tags, locations and registered devices. Saves and runs MOPs, waives lint findings, and adds synthetic check targets. Runs the setup health report and creates the overview board. Applies a configuration bundle
AdminSaves, tests and deletes the controller login. Sets up the controller tunnel and certificate (when enabled). Turns API polling and the hourly inventory refresh on or off, and manages the scrape token. Sets the write guard policy and the privacy controls. Manages notification contacts, the webhook, Jira, escalations, the heartbeat, the digest and integrations. Makes board share links. Sets branding. Invites people, changes roles and removes members. Runs the setup checklist’s privilege check and Start step, and can hide the checklist
OwnerTransfers ownership and deletes the organisation. There is exactly one owner

Viewers and operators cannot send any write to the controller. Claude’s write is refused with “This person’s role in the organisation (viewer) is read-only, so this write was not sent.” Every write by an engineer, admin or owner still goes through the write guard; see Security model.

Membership and role are read on every request, never cached in a token. A role change or removal takes effect on the person’s next call, including calls from their Claude connectors.

An admin invites a Google email address with a role; the person joins the next time they open the dashboard signed in with that Google account.

  1. Switch to the team organisation and open Configure › Team.

  2. In the Invite card, enter the person’s Email and pick a Role: admin, engineer (the default), operator or viewer. Owner can’t be granted by invite.

  3. Click Invite. The card says Invited <email>. They join the next time they open the dashboard with that Google account.

  4. Tell the person. SZ-MCP sends no invitation email.

The invite matches the verified email of the Google account the person signs in with, ignoring case. It lasts 14 days; pending invites are listed under Pending with their expiry and a Cancel button. Inviting someone who is already a member returns “That person is already a member.”

An admin picks the new role from the member’s row, or clicks Remove.

  • Role: any admin can change another member’s role to admin, engineer, operator or viewer. Your own row and the owner’s row have no role picker: another admin changes yours, and the owner’s changes only by transferring ownership.
  • Remove: after “Remove <email>?” (“Their connected Claude clients stop working for this organisation at once.”) the person loses access, and their open live boards disconnect.
  • Leave: any member except the owner can leave, after “Leave <name>?” (“You lose access to its controller, boards and alerts until someone invites you again.”).

The owner clicks Make owner on another member’s row. After confirming “Make <email> the owner?” (“You become an admin. Only the new owner can give it back.”), that member becomes the owner and you become an admin. The owner can’t leave or be removed. To step away, transfer ownership first.

Use the organisation menu at the top of the sidebar. It lists every organisation you belong to, with your role in each, and Team and organisations… opens the Team page. The active organisation is remembered for your sign-in session. The dashboard, and every card on it, shows the active organisation only.

A Claude connector is bound to one organisation, chosen on the consent screen when you add it. It does not follow the dashboard’s switch. To use Claude with another organisation, add the connector again and pick that one. See Connecting to Claude.