Team settings | Nynch Wiki Skip to content
Use cases Product Pricing Strategy Day Resources Sign in Talk to the founder
Home / Wiki / Workspace & Account

Team settings

You'll learn how to: Invite new teammates, manage their roles, see the audit log of what owners and admins have done, and configure how records are shared by default.

Time: 5 minutes to invite your first teammate. Configure-once for the policies.

Prereqs: You're an owner or admin on a plan that includes multi-seat (most paid plans). Members can see most of this in read-only mode.

Open Team settings

Open your avatar (top-right of the screen). Click Settings. Click the Team tab (or a Team-related tab if present).

The Team tab is divided into four panels:

  1. Team Settings: roster, invite, roles.
  2. Team Admin Signals: incomplete onboarding, missing integrations, follow-up gaps across the team.
  3. Team Audit Log: a chronological log of every owner / admin action.
  4. Workspace Sharing Policy: who can see which records by default.

Invite a teammate

In the Team Settings panel, click Invite Teammate (or the equivalent + button).

Fill in:

  • Email address. Required. The invite goes to this address.
  • Role: Owner, Admin, or Member. (See role definitions below.)
  • Initial pipeline access: which pipeline(s) they see by default. You can change this later.
  • Optional personal message that appears in the invite email.

Click Send. The invitee receives an email with a join link. Once they click it and sign up, they're added with the role you picked.

Pending invites appear in the roster with a "Pending" badge. You can cancel a pending invite or resend the email from the row's more-actions menu.

The three roles

  • Owner: full control. Can change billing, transfer ownership, add and remove other owners, see and edit every record in the team. Usually 1-2 owners.
  • Admin: most administrative actions but cannot change billing or remove owners. Can invite and remove members and admins, edit any record, see the audit log.
  • Member: works in the team day-to-day. Cannot invite, manage roles, see the audit log, or delete records that belong to others (unless the sharing policy is set to allow it).

You can promote a member to admin or demote an admin to member from the row's more-actions menu. Changes are logged in the audit log.

Remove a teammate

In the roster, click the row's more-actions menu and pick Remove. A confirmation dialog asks what to do with the records they owned:

  • Transfer to another teammate: pick who. The receiving teammate becomes the new owner of every record the removed person owned.
  • Reassign to primary owner: defaults to you (or the primary owner).
  • Leave unassigned: not recommended. orphaned records vanish from owner-filtered views.

Click Remove. The user is removed and their session is revoked.

Admin signals

The middle panel surfaces team-wide health issues an owner or admin should know about:

  • Onboarding gaps: teammates who haven't completed onboarding or who skipped key steps.
  • Integration drift: teammates whose Gmail / Calendar / LinkedIn connections have broken and need reconnecting.
  • Follow-up gaps: contacts on someone's rhythm list who haven't been touched in much longer than the rhythm cadence.
  • Stalled deals: opportunities on a teammate's pipeline with no activity for 14+ days.

Each signal links to the relevant teammate or record so you can take action without leaving the Team tab.

Audit log

A chronological feed of admin and owner actions:

  • Member invited / removed.
  • Role changed.
  • Sharing policy changed.
  • Team-wide settings changed.
  • Bulk delete or merge actions over a certain threshold.

Each entry shows who did what, when, and (for bulk actions) the scope of the change. Useful for retrospectives and compliance.

The audit log is owner / admin only. Members don't see it.

Workspace Sharing Policy

The fourth panel controls who can see what by default. Choose one of:

  • Private to owner: every record is private to the teammate who created it. Other teammates only see records they're explicitly added to (e.g. as collaborators on a deal).
  • Team-visible (recommended for most teams): every record is visible to every teammate by default. Owners can still mark specific deals as private for sensitive opportunities.
  • Read-by-team, write-by-owner: everyone can see everything, but only the record owner (or admins) can edit.

Picking the wrong policy at the start creates a lot of friction later (e.g. starting with Private and then needing to bulk-share when the team grows). The default for paid plans is Team-visible.

Single sign-on (SSO)

On the Team and Enterprise plans, owners and admins see a Single sign-on (SSO) card in the Team tab. SSO lets your team sign in with your company login, such as Okta, Microsoft Entra or Google Workspace.

  1. Add Nynch in your identity provider. The card shows the Nynch ACS URL and Entity ID, with copy buttons. Your IT team creates a custom SAML app with these and sets the name ID to the user's email. In Google Workspace this is Admin console → Apps → Web and mobile apps → Add custom SAML app.
  2. Connect your company login. Paste the metadata URL from that app, or upload its metadata file (Google Workspace gives you a file).
  3. Add your email domain, for example company.com. Nynch shows a DNS TXT record to add. Once it's in place, choose Check DNS. DNS changes can take up to an hour. A domain can belong to only one Nynch workspace.
  4. Sign in. Teammates choose Sign in with SSO on the sign-in page and enter their work email. The first time someone signs in this way, they join your workspace as a member, as long as you have a free seat.

Require SSO (owner only). When this is on, everyone except the workspace owner has to sign in through your company login. Password, Google and Microsoft sign-in stop working for them, including sessions that are already open, within about an hour. The owner keeps their password as a way back in if the company login ever breaks.

People can only sign in through SSO with an email on a domain you have verified. If someone's work email is on a different domain, add and verify that domain first.

Remove SSO. Your team signs in with passwords, Google or Microsoft again. Anyone who only ever signed in through your company login keeps their account, their records and their place in the team: Nynch emails them a one-time link to set a password, and the SSO card shows you what happened for each person. If someone's email did not send, or they were not reached, choose Send link next to their name. A person cannot be given a password if their email domain was never verified or if they already have a separate Nynch password account with the same email. the card says which, and they are emailed to tell them who to ask. Someone who also belongs to another workspace that still uses company login keeps signing in that way and is not emailed. If you sign in only with your company login yourself, removing it signs you out at once and you get the same email.

Removed SSO earlier? On the SSO card, choose Find people who need a password to find anyone still waiting and send them a link. This still works if your workspace has since left the Team plan. A new link can go to the same person at most once a minute, and not at all once they have set a password or signed in. from then on Forgot password on the sign-in page covers a lost password. People whose company login was removed before 6 October 2026 cannot be given a password this way. contact support for them.

If the workspace moves below the Team plan, SSO switches off and password, Google and Microsoft sign-in work again for people who have them. People who only ever signed in through SSO need a password. The owner or an admin can still open the SSO card on the lower plan and choose Remove SSO to restore password access using the same verified-domain checks and individual outcomes described above. Connecting or configuring SSO still requires Team or Enterprise.

Nynch does not offer a team-wide two-factor requirement yet.

If something goes wrong

  • Symptom: "Invite button is greyed out." → Fix: Your role isn't owner / admin. Ask an existing owner / admin to either invite the person directly or elevate your role.
  • Symptom: "Invite email never arrived." → Fix: Check the invitee's spam folder. The sender is noreply@nynch.com. From the roster, you can resend the invite. If still nothing, ask them to sign up directly at app.nynch.com and you can add them from the roster afterwards.
  • Symptom: "Pending invite for an email that already has a Nynch account." → Fix: The invitee already has a Nynch login. Cancel the pending invite, then send a fresh invite. this time they'll be added without needing to sign up.
  • Symptom: "I demoted myself from owner by accident." → Fix: Demotions don't take immediate effect on the sole owner. There must always be at least one owner. If you genuinely demoted yourself and another owner exists, ask them to promote you back. If you're sole owner, the demotion was rejected and you should still be owner.
  • Symptom: "Audit log is empty." → Fix: New teams have no audit entries yet. The log fills as owners / admins take actions.
  • Symptom: "Sharing policy change didn't seem to do anything for existing records." → Fix: Sharing policy applies to records created AFTER the change. Existing records keep their previous visibility. Bulk-update existing records via the Contacts / Deals table if you need to retroactively change them.

FAQ

Q: How do I team settings? Invite new teammates, manage their roles, see the audit log of what owners and admins have done, and configure how records are shared by default.

Q: What do I need before I start? You're an owner or admin on a plan that includes multi-seat (most paid plans). Members can see most of this in read-only mode.

Q: How long does this take? About 5 minutes to invite your first teammate. Configure-once for the policies.

Q: Invite button is greyed out? Your role isn't owner / admin. Ask an existing owner / admin to either invite the person directly or elevate your role.

Q: Invite email never arrived? Check the invitee's spam folder. The sender is noreply@nynch.com. From the roster, you can resend the invite. If still nothing, ask them to sign up directly at app.nynch.com and you can add them from the roster afterwards.

Related: View the workspace audit log.