# Team and organization settings

An **organization** is the workspace that owns a portfolio: every upload, field, segment, and loan in Vintage belongs to exactly one organization, and Vintage never shows one organization's data to anyone who is not a current member of it. The people in an organization are its **members**, and each member has one of three roles: **admin**, **editor**, or **viewer**. The settings below belong to the organization rather than to one person: its name, its team, and which networks may reach it. They end with switching between organizations if you belong to more than one.

## Where these settings live

Open **Settings** from the bottom of the main navigation, or choose **Org Settings** from the organization switcher at the top of the sidebar. Settings has four areas:

| Area | What it holds | Who can see it | Who can change it |
|---|---|---|---|
| **Organization** | The organization's name | Everyone | Admins |
| **Profile** | Your own name, email, password, and devices | Everyone, for themselves | Everyone, for themselves |
| **Team** | Members and pending invites | Everyone | Admins |
| **Security** | The IP allowlist | Admins only | Admins |

Your profile is covered on [Profile and security settings](/account/profile-and-security-settings/).

## The three roles

| Role | Shown as | In short |
|---|---|---|
| **Admin** | Admin | Everything an editor can do, plus managing the team and renaming the organization. |
| **Editor** | View and update | Uploads data, manages custom fields, and edits how the portfolio's data is read. Cannot manage the team or rename the organization. |
| **Viewer** | View only | Sees the portfolio and models it. Cannot upload or change anything. Sees the organization's settings and team read-only. |

The person who creates an organization is its first admin. Roles are enforced, not merely hidden: a viewer who reaches an editing screen by any route sees a page saying their role does not include access, and the action itself is refused. The full matrix is on [Roles and permissions](/reference/roles-and-permissions/).

## Renaming the organization

Under **Organization**, an admin edits the name and it **saves automatically** a moment after they stop typing. There is no Save button. Everyone else sees the name read-only, with a note that only an admin can change it.

## The Team list

**Team** lists the organization's members and any pending invites:

| Column | What it shows |
|---|---|
| **Name** | The member's display name. Your own row is tagged **You**. |
| **Email** | Their sign-in email, or the address an invite was sent to. |
| **Role** | Admin, View and update, or View only. |
| **Status** | **Active** for a member, **Pending** for an invite not yet accepted. |
| **Actions** | What an admin can do with that row. |

Admins see controls on every row except their own. Editors and viewers see the same table **read-only**: roles as plain text, no controls, and the invite form shown but disabled with a note that only admins can invite.

### Inviting a teammate

1. Under **Invite a teammate**, enter the person's **Name** and **Email**.

2. Choose a **Role**: **View only** (the default, and the safest) or **View and update**. To make someone an admin, invite them first and change their role once they have joined.

3. Press **Send invite**. The person receives an invite email, and a **Pending** row appears in the table.

**Inviting someone who already has a pending invite updates that invite** rather than creating a second one. The name, the role, and who invited them are replaced with your new answers, and the invite email is sent again. So if you invited someone at the wrong role, invite them again with the right one; they are never left holding two conflicting invitations.

Inviting someone who is **already a member**, including yourself, is refused: "That person is already on your team."

### What the invited person sees

- **Someone new to Vintage** gets an email linking to a sign-up page with their name and email already filled in. They finish signing up and verify their email, and are added to your organization at the role on the invite automatically. They are not asked to create an organization of their own. Someone invited to several organizations this way joins all of them and works in one at a time.
- **Someone who already has an account and belongs to an organization** sees a **Pending invitations** prompt the next time they are signed in, with **Accept**, **Decline**, and **Not now** for each invite. Accepting adds them to your organization and switches them into it. Declining clears the invite. Not now puts the prompt off until next time.
- **Someone who already has an account but no organization yet** meets the invite as a **Join your team** step, before they would be asked to create an organization, so a teammate is never pushed into setting up a throwaway organization while yours is waiting for them.

A pending invite does not expire. It stays open until the person accepts or declines it, or an admin removes it.

### Managing pending invites

Each pending invite row has two actions:

- **Resend** sends the invite email again.
- **Remove invite** withdraws it, after a confirmation. The address can no longer join unless you invite it again, so a mistyped invite can be taken back.

### Changing a role

An admin changes any other member's role from the **Role** menu on that member's row, to Admin, View and update, or View only.

### Removing a member

An admin removes a member with the remove action on their row, after a confirmation. The person loses access to the organization. Their work stays: their past uploads remain in the organization's history and still show who uploaded them. Removing someone from an organization never deletes their Vintage account.

### What the Team list will not let you do

- **Change or remove yourself.** Your own row has no controls.
- **Leave the organization without an admin.** Any change that would leave no admin is refused: "An organization needs at least one admin." Promote someone else first.

Every refusal is explained on screen in plain language. A role menu never silently snaps back.

### The "Vintage support" member

While the Vintage team is setting up a new organization's first portfolio, a Vintage teammate joins the organization as an editor to finish the work. They appear on your Team list labeled **Vintage support**, with the ordinary remove control on their row, so an admin can end that access at any time. When the work is done, they leave and the row disappears. See [Your first upload](/uploading/your-first-upload/).

## Restricting which networks can reach your organization

By default, your organization can be reached from any network. An admin can restrict it to a list of approved networks, called an **IP allowlist**, under **Settings › Security**. The Security area is visible only to admins: other members do not see it in Settings, and going to it directly is refused.

Each rule is one of:

- a single **IPv4** address, such as `203.0.113.4`;
- a single **IPv6** address;
- a **CIDR range**, an address followed by a slash and a prefix length that covers a whole block of addresses, such as `203.0.113.0/24` (every address from `203.0.113.0` to `203.0.113.255`) or `2001:db8::/32`.

Each rule can carry an optional label, such as the office it belongs to. Use **Add IP address** to add a rule and the remove control to delete one, then **Save changes**. The whole list saves at once.

**With no rules**, the organization is reachable from any network, and the panel says so. **With one or more rules**, only a person connecting from an address that matches a rule can reach the organization's signed-in pages and its data. This is enforced by Vintage itself, not by hiding navigation: a request from any other address is refused.

**Vintage will not let you lock yourself out.** The panel shows your own current IP address. A save that would not include it is refused, with a message naming the address to add.

**Caution:** The allowlist applies to every member, admins included. If your team works from more than one office, or from home, add each network before you save, or those members will be turned away.

### What a blocked member sees

Someone whose address is not on their active organization's list is sent to a page that says **Your IP address isn't allowed** and shows the address they are connecting from. It never shows the allowlist itself. From there they can switch to another organization they belong to (the blocked one is disabled in the list), **Log out**, or contact Vintage support.

## Belonging to more than one organization

You can be a member of several organizations, and you work in **one at a time**, your **active organization**. Everything you see (the portfolio, uploads, fields, segments, Modeling) belongs to the active organization.

The **organization switcher** at the top of the sidebar shows the active organization's name. Its menu lists the organizations you belong to, **Org Settings** for the active one, and **Create organization**. Choosing another organization switches the whole app to it. Vintage remembers your most recently used organization across sign-outs and devices, so you return to where you left off.

**Creating an organization** from the switcher asks only for a name, and makes you its admin. A new organization's first portfolio is set up by the Vintage team; see [Your first upload](/uploading/your-first-upload/).

**If you are removed from your active organization**, Vintage quietly switches you to another organization you belong to rather than showing you nothing. If it was your only organization, your Vintage account remains, and your next visit takes you to the step for creating an organization, or to **Join your team** if an invite is waiting for you.

## Related

- [Accounts and organizations](/getting-started/accounts-and-organizations/)
- [Roles and permissions](/reference/roles-and-permissions/)
- [Profile and security settings](/account/profile-and-security-settings/)
- [Security and data protection](/reference/security-and-data-protection/)
- [Your first upload](/uploading/your-first-upload/)
- [Emails Vintage sends](/reference/emails-vintage-sends/)