# Member management

Within a workspace, you need to decide **who can enter the current workspace** and which AI Studio features members can use.
Complete operations are available under **User Permissions** in the sidebar. This page explains the scenarios, entry points, and boundaries without duplicating the main permissions documentation.

## Where to manage members

| What you want to do | Where to go |
| --- | --- |
| Invite an existing account to the workspace | [User Permissions · User management](../permissions/users.md) |
| Assign or adjust roles for a member | [User Permissions · User management](../permissions/users.md) |
| Create or configure roles and permission points | [User Permissions · Role permissions](../permissions/roles.md) |
| Organize members with tags | [User Permissions · User management](../permissions/users.md) |
| Enable, disable, or remove a member | [User Permissions · User management](../permissions/users.md) |

Entry point: after entering the workspace, open **User Permissions** from the sidebar.

## Recommended order

1. In [Role permissions](../permissions/roles.md), confirm whether a suitable role already exists. You can start with a built-in role.
2. In [User management](../permissions/users.md), invite the member and assign at least one role.
3. When a member's responsibilities change, adjust their role instead of using tags as a substitute for permissions.

Tags are only for organization and identification; they **do not grant feature permissions**.

## Boundaries with accounts and MatrixOne

| Dimension | What it controls | Entry point |
| --- | --- | --- |
| Workspace members and roles | Who is in this workspace and which AI Studio features they can use | User Permissions (linked from this page) |
| Personal account | Your own profile, password, sessions, and related settings | Account settings in the top bar |
| Permissions within MatrixOne databases | Database users and SQL grants | [MatrixOne permissions](../../matrixone/permissions.md) |

Inviting a member adds an **existing AI Studio account** to the workspace; it does not register a new account.
