# Teams

> Outside of grouping users together, teams offer control access to workspaces and to workspace resources such as environments and managed and unmanaged connections.



Organizations are the basic unit of multi-tenancy inside of Layer5 Cloud. Organizations can have any number of teams. Teams can have any number of users. Users can belong to any number of teams. Users may belong to any number of organizations.

Outside of grouping users together, teams offer control access to workspaces and to workspace resources such as environments and managed and unmanaged connections.

## Example: Orbital Labs Teams

The following teams illustrate how organizations use teams to segment access and responsibilities. Follow the full story at [Meet Five and the Cast]().

<img src='images/team-of-fives.svg' alt="Team of Fives" style="width:120px; float:right; margin-left:1.5rem; margin-bottom:1rem;" />

<div class="td-card-group card-group p-0 mb-4">
<div class="td-card card border me-4">
<div class="card-header">
      <strong>Infrastructure Team</strong>
    </div>
<div class="card-body">
    <p class="card-text">
        <p><strong>Organization:</strong> Orbital Labs
<strong>Team Admin:</strong> Zara Osei
<strong>Members:</strong> Five</p>
<p>Controls access to production and staging workspaces (<code>orbital-production</code>, <code>orbital-staging</code>). Zara manages the keychain permission matrix and approves environment assignments. Five handles day-to-day platform operations and occasionally discovers undocumented feature behavior.</p>
</p>
      </div>
  </div>

<div class="td-card card border me-4">
<div class="card-header">
      <strong>Development Team</strong>
    </div>
<div class="card-body">
    <p class="card-text">
        <p><strong>Organization:</strong> Orbital Labs
<strong>Team Admin:</strong> Maya Chen <em>(also Org Admin)</em>
<strong>Members:</strong> Rex Park, Jordan Reyes</p>
<p>Controls access to the development workspace (<code>orbital-dev</code>). Rex deploys often; Jordan designs infrastructure that is architecturally ambitious. Maya ensures neither of them touches production on a Friday afternoon.</p>
</p>
      </div>
  </div>

</div>








<div class="alert alert-custom" style="border-color: #3772ff;" role="alert">
  <h4 class="alert-heading" style="color: #3772ff;">Info</h4>
  
      An Org Admin may also serve as a Team Admin — Maya Chen holds both roles at Orbital Labs. See <a href="/cloud/concepts/identity-and-security/roles/">Roles</a> for more on how role assignments stack.
  
</div>



## Add a Team

To apply different settings to a set of users, create a child new team below your top-level organization and place them in it. You can then apply unique settings to that team, like access to a workspace and their a specific set of environments.

A team is simply a group that an administrator can create in the Google Admin console to apply settings to a specific set of users. By default, all users are placed in the top-level (parent) organizational unit. Child organizational units inherit the settings from the parent, but can be changed to fit the needs of the child organizational unit.

Below the top-level organization, you can add as many teams as you want - at the same level. Hierarchal teams are not currently supported. When you change a setting at the higher level organization, the settings for all child teams that inherit that setting also change. Custom settings at the team level, however, remain unchanged.

>Learn more about the [organizational structure](/cloud/concepts/identity-and-security/).







<div class="alert alert-custom" style="border-color: #3772ff;" role="alert">
  <h4 class="alert-heading" style="color: #3772ff;">Team Ownership</h4>
  
      If you are the current team owner, you can’t remove yourself from the team until you transfer ownership to another team administrator.
  
</div>









<div class="alert alert-custom" style="border-color: #3772ff;" role="alert">
  <h4 class="alert-heading" style="color: #3772ff;">Removing a Member from the Organization</h4>
  
      Removing a member from an organization also ends their membership in that organization&rsquo;s teams, and the permissions those team memberships granted. See <a href="/cloud/concepts/identity-and-security/users/user-management/">User Management</a>.
  
</div>



## Delete a Team

Deleting a team permanently removes the team and its memberships from the organization. This action dissolves the team but does not delete user accounts or associated resources.

### What Happens When a Team Is Deleted?

* The team is permanently removed.
* All memberships associated with the team are removed.
* User accounts remain in the organization.
* Associated resources remain intact.
* Team ownership is removed along with the team.







<div class="alert alert-custom" style="border-color: #3772ff;" role="alert">
  <h4 class="alert-heading" style="color: #3772ff;">Team Deletion</h4>
  
      Deleting a team removes team memberships and ownership, but does not delete user accounts or associated resources.
  
</div>



### Example

Suppose Team A contains Alice and Bob and is associated with several resources.

After deleting Team A:

* Team A no longer exists.
* Alice and Bob remain users in the organization.
* Team memberships are removed.
* Associated resources continue to exist.


## Open Team Invite

The "Open Team Invite" feature allows administrators to use shareable "Team Invite Links" for users to join a particular team. This link-based invitation method functions much like an [Open Org Invite Link](https://docs.layer5.io/cloud/guides/organizations/org-management/), but is tailored for team-specific invitations and provides a direct alternative to adding members manually.

![Process of open team invite](images/open_team_invite.gif)

### When to Use

- **Large-Scale Member Recruitment:** Efficiently integrate many new members into project teams, especially during organizational expansion.

- **Structured Self-Service Enrollment:** Supports efficient, self-service team setup for urgent initiatives (e.g., agile sprints, training cohorts).







<div class="alert alert-custom" style="border-color: #3772ff;" role="alert">
  <h4 class="alert-heading" style="color: #3772ff;">For Organization-Specific Invitations</h4>
  
      If your goal is to invite users only to a specific organization (and not directly to a team as part of the same invitation), please refer to the documentation on <a href="https://docs.layer5.io/cloud/guides/organizations/org-management/">Open Org Invite Link and User Management</a>.
  
</div>



### How it Works

1. **Copy Team Invite Link:** Click the **copy** button to get the "Team Invite Link".[^1]
2.  **User Onboarding with Team Invite Link:** When a user clicks the "Team Invite Link," the system handles their onboarding as follows:
    * **If the user has no system account:** They are guided through the account registration process. Upon successful registration, they are automatically added to **both** the relevant organization and the specific team.
    * **If the user has a system account but is not in the target organization:** Upon using the link, they are added to **both** the organization and the specific team.
    * **If the user is already in the organization (and has an account):** Upon using the link, they are added to the specific team.
3.  **Manual Alternative:** As an alternative, administrators can always manually add existing organization members to a team.

[^1]: If the direct way to copy this link isn't fully visible or working correctly in the current version, this is a known issue that we plan to fix in an upcoming update.

