Team
Vesper is tenant-scoped: everyone from your organization shares the same workspace, environments, agent history and billing. The Team page is where admins manage who is in it.
Roles
| Role | Can do |
|---|---|
| User | Ask questions, chat with the agent on existing environments, view answers and changes. |
| Admin | Everything a user can, plus: invite and remove members, toggle roles, register and delete environments, change agent modes, mint enrollment tokens, approve changes, manage billing. |
The first person from an organization to sign in becomes admin automatically. Admins cannot change their own role or remove themselves, so a tenant can never lock itself out.
Inviting a teammate
- Open Team and send an invite to their email address.
- The invite is tied to Wazuh ID: the teammate signs in at
vesper.wazuh.com with that email, registering
at
id.wazuh.comfirst if needed, and lands directly in your organization. - Until they do, the invite shows as pending, labelled "waiting for them to sign in with Wazuh ID", and can be revoked.
Because identity is ecosystem-wide, a teammate who already uses another Wazuh Labs service signs straight in with the account they already have.
Managing members
From the member list, admins can:
- Toggle any other member between admin and user.
- Remove a member from the team. Their access ends immediately, while the tenant's data stays, including answers, environments and ledger entries.
- Revoke a pending invitation before it is accepted.