Skip to main content
Cedros

Removing a teammate’s access

Remove a teammate from the correct organization, cancel unwanted invitations, review remaining access, and verify the handover.

Remove someone from the correct Cedros organization, check that their team access has ended, and review any separate access they used for your business.

Use this guide when someone leaves your team or no longer needs membership. If they still need to work with you but should have fewer permissions, use Choosing roles and managing permissions instead.

Know what you are removing

Removing a team member ends their membership in the selected organization. It is not the same as deleting their Cedros account, signing them out of every device, or removing them from every site and service your business uses.

Choose the action that matches the situation:

  • They have not accepted an invitation: cancel the pending invitation. There is no accepted membership to remove yet.
  • They have joined and should leave this organization: remove the team member using the procedure below.
  • They only need fewer responsibilities or fewer admin pages: change their role or page permissions.
  • They know a shared password or have separate access: review that access as well as their Cedros membership.

Do not use Remove restriction in Manage Permissions to remove a teammate. That action opens a restricted admin page to more teammates with admin access.

Prepare the handover

Before removing a member, confirm:

  • The organization and person. Check the selected account and the teammate’s identity. A portal account and an individual site can have separately managed teams.
  • Your authority. Removing another person requires an owner or administrator with the necessary team-management permissions. Only an owner can remove another owner.
  • A remaining owner. Cedros will not let an organization lose its last owner. An Administrator role does not count as an Owner for this safeguard.
  • Responsibility for ongoing work. Identify who will handle their drafts, scheduled work, customer conversations, bookings, and connected services. Membership removal does not perform a general handover of those responsibilities.
  • Other access to review. List the sites, mailboxes, shared logins, integrations, and external services they used.

Do not delete business content simply because its author is leaving. Review what should be retained and who needs access to it. If the departure involves suspected account misuse, ask the owner or support to help contain access promptly; do not delay that work for a routine handover.

If the departing person is the only owner, arrange an ownership change through the supported process before trying to remove them. The standard Portal role form offers Member and Administrator, so it cannot complete that ownership change for you.

Remove the teammate in the customer portal

Use these steps when the customer portal exposes Team actions for the organization you manage. On cedros.ai, open Portal Team, or choose Team from the portal account menu.

  1. Sign in and select the account or organization the teammate should leave.
  2. Open Team and review its member information. Confirm that the person is an existing member, not only a pending invitee.
  3. Under Team actions, expand Remove a team member.
  4. In Team member, choose the correct person. Recheck the selected account and person before continuing; the form may already select an entry when only one is available.
  5. Select Remove member once. This submits the removal; do not rely on a separate confirmation dialog.
  6. Wait for Team member removed. and allow the team information to refresh. Confirm that the person is absent from that organization’s member list.

If the action reports an error or the list does not refresh, check the current member list before submitting again. A request can complete even when the response or subsequent refresh fails.

If the form shows an empty or unfamiliar identifier field instead of a recognizable person, stop and refresh the team information. Do not guess a user ID or use the email address as a substitute.

If you are in an individual site’s admin

The standard Users → Team page displays team information, Manage Permissions, and Invite Team Members. It does not provide the Portal’s member-removal form.

Use the team-management page for that site’s organization, or ask its authorized owner or support to remove the membership. Do not remove someone from an unrelated portal account simply because that account has an available removal button.

The Mail addresses section on the Team page manages email addresses. Deleting an address there is not a substitute for removing organization membership.

Cancel invitations that should no longer work

An unaccepted invitation and an existing membership are separate records. Review pending invitations for the departing person in the same organization, and cancel any that should no longer be usable.

Where the Portal exposes the action:

  1. Open Team actions and expand Cancel an invitation.
  2. Choose the correct entry in Pending invitation.
  3. Select Cancel invitation and wait for Invitation cancelled.
  4. Confirm that the invitation is no longer listed as pending.

Cancellation does not remove someone who has already joined. Likewise, removing a member is not a reason to assume every old invitation has been cancelled. For the full invitation workflow, see Inviting teammates and accepting invitations.

Review access that membership removal does not cover

Work through the items that apply to this person. Removal from one organization is not a universal access-revocation switch.

Other organizations and individual sites

Check separately managed Cedros accounts and sites where they were also a teammate. Remove only the memberships intended to end. Their personal account and unrelated organization memberships are separate from the one you removed.

If they ever used a shared built-in owner login, their own membership removal cannot change that shared password. Have the authorized owner replace the shared credential and review its sessions through the supported account controls.

Named-person page permissions

In each relevant site, review Users → Team → Manage Permissions for explicit grants naming the person. Use Edit access to remove outdated named-person grants, then Save access. Keep the intended page restriction in place.

Do not assume an old grant disappears automatically when membership changes. If the directory cannot resolve a name, verify the person before removing the entry. See Choosing roles and managing permissions for exact controls and directory warnings.

Mailboxes, shared credentials, and integrations

Review mailbox access, email-client credentials, forwarding destinations, and any provider accounts the person controlled. Confirm separately that the person can no longer use those mailboxes or provider accounts; removing team membership does not confirm that every email connection has been revoked.

Check the resulting mailbox status and who can still receive or read business mail. Arrange any needed handover before changing or deleting an address.

Replace shared passwords or tokens the person knew, and revoke their separate service access where appropriate. Update the business systems that depend on a replaced credential, then check that they still work. A connector using the departing person’s own provider account may need to be connected under an appropriate continuing account.

Sessions and existing copies

Do not treat member removal as Sign out all devices. A person may remain signed in to their account while no longer being a member of the organization. The relevant check is whether they can still access the organization’s protected information or perform its actions.

The profile session controls manage the signed-in user’s own sessions; they are not a tool for signing out another teammate. See Reviewing and signing out active sessions when reviewing your own account or a shared account you are authorized to manage.

Removal cannot recall files, emails, screenshots, or other information someone already copied outside Cedros.

Confirm the removal is complete

Check both the membership change and the separate access you identified:

  • Reload the correct organization’s team list and confirm the person is no longer a member. A general site directory or an empty roster with a loading error does not confirm the removal.
  • Confirm that unwanted pending invitations are cancelled.
  • Review relevant site-specific grants, mail access, shared credentials, and external service access.
  • If a cooperative access check is appropriate, have the former teammate use their own account to reload the organization’s protected page and confirm they cannot use it. Do not ask for their password or impersonate them.
  • Confirm that the remaining team can still perform essential work after any credential or ownership handover.

An already-open screen may still display previously loaded information. A visible page title alone does not establish current access. If fresh protected data or actions remain available after removal, record the site, organization, action, and time, and ask the owner or support to investigate.

Troubleshooting

Remove a team member is missing or access is denied

Confirm that you are in the customer portal for the intended organization and signed in with appropriate team-management permissions. An ordinary member or a read-only portal view may not expose the action. Ask an authorized administrator or owner to perform the removal.

If the target is an owner, another owner must handle it. Do not try to bypass the restriction by deleting unrelated records or changing page visibility.

Cedros will not remove the last owner

Keep an owner in place and arrange the supported ownership change first. Promoting someone to Administrator does not satisfy the owner requirement. Contact the current owner or support if you cannot complete the handover.

The person is missing from the list, or the request failed

Check the selected organization and whether the person is still a pending invitee. Reload to rule out stale information or a removal another administrator already completed. If the member list cannot load, restore that view before treating absence as success.

If you see Team member removed. but the refreshed list still includes the same membership, or repeated attempts fail, stop and contact support with the exact error and time. Do not delete the user’s whole account as a workaround.

You removed the wrong teammate

Confirm that the original removal completed, then send a new invitation to the intended account with the appropriate role. The person must accept it again. Recheck page grants, mailbox access, and any credentials changed during the handover; reinviting someone is not a complete undo of those separate changes.

For help, use Getting help and reporting a problem. Include the site, organization, affected action, expected result, time, and error text. Share account-identifying details only through the appropriate support channel, and never send passwords, session tokens, or invitation links.