> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stackone.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage Team

> Bring people into the organization, and make sure they lose access when they leave.

<Note>
  [**Organization Admins**](/secure/identity-and-access/roles-and-groups/organization-roles) manage who can access the StackOne organization.
</Note>

Manage everyone in the organization, from the day they join to the day they leave.

Users join in one of three ways:

<CardGroup cols={3}>
  <Card title="Invite Users" icon="envelope" href="/secure/identity-and-access/manage-team/invite-users">
    An **Organization Admin** sends an email invite and picks the user's role.
  </Card>

  <Card title="Just-in-Time Provisioning" icon="bolt" href="/secure/identity-and-access/manage-team/jit">
    Users join when they sign in with SSO and aren't a member yet.
  </Card>

  <Card title="SCIM Provisioning" icon="arrows-rotate" href="/secure/identity-and-access/manage-team/scim/overview">
    The identity provider adds and removes users as the directory changes.
  </Card>
</CardGroup>

## Using multiple provisioning methods

An organization can use more than one of these at once. When multiple methods are used, user management can be taken over by the identity provider (IdP):

| User's current status | Email invitation | Just-in-Time Provisioning | SCIM Provisioning |
| - | - | - | - |
| **Already a member** | Can't be sent to an existing member. | Leaves them as they are. | Starts managing them when the IdP assigns them. |
| **Invited, but hasn't accepted yet** | Adds them with the invitation's role when they accept it. | Doesn't add them. They join only by accepting the invitation. | Adds them with the role the IdP sends, not the invitation's. The invitation should be removed. |
| **Neither** | Adds them when they accept it. | Adds them the first time they sign in to StackOne with SSO. | Adds them when the IdP assigns them. |

## Removing access to the organization

Disabling or deleting a user ends their access to the organization, including any [AI platform](/connect/ai-platforms/overview) connections they made to it.

* **Disable** keeps their roles, group memberships and seat, so enabling them again restores their access.
* **Delete** removes their roles and group memberships, and frees their seat. To give them access again, invite them back.

<Note>
  An organization's last active **Organization Admin** cannot be disabled or deleted.
</Note>

How to remove someone depends on how the organization adds people:

| The organization uses | Remove them by |
| - | - |
| Invitations only | Disabling or deleting them on the **Members** tab of [**Organization > Manage Team**](https://app.stackone.com/organization/manage_team). |
| Just-in-Time Provisioning | Following the steps in [Just-in-Time Provisioning > Remove access to the organization](/secure/identity-and-access/manage-team/jit#remove-access-to-the-organization). |
| SCIM Provisioning | Following the steps in [SCIM Provisioning > Deprovisioning](/secure/identity-and-access/manage-team/scim/overview#deprovisioning). |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.