When someone joins

Invite the person to the relevant organization or code group using their own email. Grant only the group role they need. Ask them to secure their account, register a passkey if available, and store recovery codes away from Team2FA. Confirm the underlying service permissions match the task.

When a role changes

Review group access and user group membership. Remove access that no longer fits. Inspect the activity log to understand recent access without relying on chat messages. Restrict shared seeds to the smallest practical team.

When someone leaves

Suspend membership and revoke Team2FA sessions. Remove their access to the external account, end the external account sessions and rotate its TOTP seed if they had access to that seed. Revoking Team2FA alone cannot erase a copied seed or end a third party session.