# Members and Teams

> Part of the NocoDB documentation (Apps). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/apps/members-and-teams
Last updated: 2026-10-05

Control who can use a NocoDB app and what they can do in it with app teams, members and action grants.

<AskNocoAI>
  <Prompt>
    Add a [Managers] team that can [approve and reject requests]
  </Prompt>

  <Prompt>
    Let the [Members] team see only the [tickets] assigned to them
  </Prompt>

  <Prompt>
    Add a screen in the app where admins can invite people
  </Prompt>
</AskNocoAI>

A NocoDB app uses **teams** to control access. A team is a group of people in the app. Each team has a list of **grants**: the actions that its members can run. A person can open the app only when they are in a team that has at least one grant. You manage teams in **App Settings** → **Access**.

<img alt="Teams in the Access tab" src={__img0} placeholder="blur" />

## Built-in teams

Every app starts with two teams:

| Team        | Who is in it                                                                                                          | What they can do                                                    |
| ----------- | --------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------- |
| **Admin**   | All base owners and creators, and the people you add. "Manages people. Only an admin can make someone else an admin." | Every action that the app publishes, and the grants you add on top. |
| **Members** | "Everyone on the base, with the actions granted below."                                                               | Only the actions that you grant to the team.                        |

The **Everyone on this base** toggle on the **Members** team controls whether base members can use the app. Turn it off to close the app to base members. The grants of the team stay, so you can turn it on again later.

## Create a team

1. Open **App Settings** → **Access**.
2. Click **New team**.
3. Type a **Team name**. You can also type a description: "What is this team for? (optional)".
4. Click **Create**. Then add members and grants to the team.

To rename or delete a team, open the team menu and select **Rename** or **Delete team**. Members of a deleted team keep their base access.

## Add members to a team

1. On the team card, click **Add members**. A dialog opens.
2. Select a tab:
   * **Base users**: click a person who already has access to the base.
   * **Teams**: click a workspace team. All members of the workspace team join the app team.
   * **Invite**: type the email address of a person outside the base, then click **Invite**. "Give someone outside this base access to only this app. They get no other base access."
3. Click **Done**. The people and teams show on the team card.

<img alt="The Add members dialog" src={__img1} placeholder="blur" />

People without a NocoDB account get an invite email with a sign-up link.

## Grant actions to a team

Actions are the operations that the app can run, for example "create booking" or "send invoice". NocoAI creates them when it builds the app. A grant lets the members of a team run an action.

1. On the team card, find **Actions this team can invoke**.
2. Search for an action, and select it. To grant all actions of one group, select **Every action in \[namespace]**.
3. [Deploy](/docs/apps/deploy-app) the app. "Grants take effect the next time you publish this app."

<img alt="Actions this team can invoke" src={__img2} placeholder="blur" />

A team with no grants cannot run any action. Its members cannot open the app.

## How people open the app

| Person                         | How they open the app                                                   |
| ------------------------------ | ----------------------------------------------------------------------- |
| Base member                    | Click **App** in the mini sidebar of the base, or open the app address. |
| Person invited to the app only | Open the app address and sign in with their NocoDB account.             |

NocoDB checks the team of the person when they open the app. When they are not in a team with grants, the app shows "You don't have access to this app."

## Limit records for each team

Teams can see only part of the data, for example "members see only their own requests". Ask NocoAI for the rule in the [AI app builder](/docs/apps/app-builder). NocoAI adds a [record-level security](/docs/product/collaboration/record-level-security) policy for the team. App teams also show as **App teams** in the policy editor of record-level security.

## Good to know

* A person is in only one team of an app, plus **Admin**. When you add a person to a second team, NocoDB moves them out of the first team.
* Base owners and creators can always build and use the app, with every action allowed.
* Visitors who do not sign in use the grants on the **Public** tab. See [Public access](/docs/apps/public-access).
* Removing a person from a team removes only what that team allows in the app. Their base access does not change.

## Availability

* Workspace teams in app teams are available on the **Business** plan and above.
* Record-level security for app teams is available on the **Scale** plan and above.

## Related

* [Public access](/docs/apps/public-access)
* [Deploy an app](/docs/apps/deploy-app)
* [Roles and permissions](/docs/product/collaboration/roles-and-permissions)
* [Secure vibe coding](/docs/apps/security)

---

## Related pages

- [Apps](https://nocodb.com/docs/apps.md): NocoDB Apps is an AI app builder for creating enterprise-grade work apps: describe the app, and NocoAI builds it on the data you already have, with teams, permissions, an API and an MCP server.
- [Vibe Coding with NocoDB Apps](https://nocodb.com/docs/apps/vibe-coding.md): Vibe coding is making software by describing it to AI. NocoDB Apps bring vibe coding to enterprise-grade work apps, on your own data, with teams, permissions and safe deploys.
- [Create an App](https://nocodb.com/docs/apps/create-app.md): Create a NocoDB app with AI: describe the app, and NocoAI builds it on your data. Start from the App tile in a base, with Build with AI, or in the NocoAI chat.
- [AI App Builder](https://nocodb.com/docs/apps/app-builder.md): Build and change enterprise-grade work apps in NocoDB's AI app builder: describe a change to NocoAI in the chat, and test it in the live preview.
- [Data for Apps](https://nocodb.com/docs/apps/data.md): Build NocoDB apps on the data you already have: NocoDB tables, your own PostgreSQL or MySQL database, and data that syncs from tools such as GitHub and HubSpot, with no record limit.
- [Secure Vibe Coding](https://nocodb.com/docs/apps/security.md): How NocoDB Apps keep AI-built work apps safe: teams and action grants, record rules, reviewed public pages, secrets in connections, scoped API tokens, environments and version restore.
- [Public Access](https://nocodb.com/docs/apps/public-access.md): Make pages of a NocoDB app public, and choose which actions visitors can run without signing in.
- [Deploy an App](https://nocodb.com/docs/apps/deploy-app.md): Deploy a NocoDB app to make the current build live at its address, review risky changes before they go live, and restore an earlier version.
