Skip to main content
People join orriven at the organization level and receive a default role there. Inside each Business Unit that role can be overridden — tightened or raised — without changing what the person can do anywhere else.

Inviting members

  1. Open Members in the organization section of the console.
  2. Choose Invite, enter the person’s email address, and pick the organization role.
  3. The invitation appears under Pending invitations until it is accepted.
The Members page lists everyone in the organization and their default roles.

The roles

The same role names are used at both levels: A person’s organization role is the default everywhere. A Business Unit role applies inside one unit only.

How a person’s role resolves in a Business Unit

When someone opens a Business Unit, the effective role is decided in this order:
  1. Organization owners and admins always have access, with that role. An organization cannot be locked out of its own Business Unit.
  2. An explicit role granted in that Business Unit wins next. On the unit’s Members page, the “Role here” column shows it; anything not overridden shows as Inherited.
  3. Otherwise the organization role is inherited — unless the Business Unit is restricted, in which case there is no fallback and the person has no access.

Setting per-unit roles

Open the Business Unit, then its Members page. Each row shows the person’s organization role and their role here. Pick a different role to override. Choose Reset to organization role to remove the override and return to inheriting.

What this means when setting up a team

Examples for an admin:
  • Most companies need only organization roles. Give planners the Planner role at the organization. Every Business Unit inherits it. Overrides are for exceptions.
  • Contractor for one project: invite as organization Viewer, then grant Planner inside the one Business Unit they work in. All other units are view-only.
  • Confidential unit: mark the Business Unit restricted in its settings, then explicitly grant a role to each person who should be inside. Everyone else — whatever their organization role — cannot see the unit exists. Organization owners and admins still can.
  • Demote locally: a Planner who should only observe one sensitive unit can be overridden to Viewer there, keeping Planner everywhere else.

Rules to know

  • No access looks like “not found”, not “no permission”. A member without access to a restricted unit does not see it listed and gets a not-found page on its URLs. The unit’s existence is itself confidential.
  • An override is one unit only. Granting Planner in one Business Unit says nothing about any other unit.
  • Owners and admins cannot be restricted out. Restricted mode removes the organization-role fallback for regular members. Owners and admins always retain access.
  • Absence of an override means “inherit”. Resetting a role is not a removal from the unit — the person keeps whatever the organization role and the unit’s access mode give them.
  • Membership of the organization is managed on the organization Members page. Business Unit pages only decide roles, never who is in the company.
Every role change — invitations, overrides, restriction toggles — is recorded in the audit log: who granted access, and when.