Invite your team
Members, seats, and what does not count as one.
Written By Dustin
Last updated About 6 hours ago
Invite people by email from your organization's members page. They need a TOVIO account; the invitation links to creating one.
What consumes a seat
Only active human members. Explicitly not:
pending invitations, until accepted
AI agents, however many you run
CI identities
service identities
This matters for anyone planning an agent fleet: agents are billed as sessions, never as seats, and no plan caps how many of them may run at once.
Seats buy allowance as well as access
On Business and Enterprise the included storage, agent sessions and CI-minutes are per seat, so adding a person raises them. CI is the exception in shape: it is clamped between a floor and a ceiling, so the first seats already carry the floor and the last ones stop adding. The plans article has the arithmetic and a table of worked seat counts.
Seat limits
Business is capped at 50 seats and the cap is enforced, not a guideline. Above that, Enterprise. Personal is a single seat and cannot have members — it is for one person, not a small team. An organization with no active human seat is not a valid state.
When seats change
Adding a seat prorates immediately: you are charged for the remainder of the period. Removing one takes effect at renewal rather than immediately, so mid-period reductions do not produce a refund.
What waits for renewal is the charge, not the access. Removing someone from the organization ends their access when you remove it.
The practical consequence: add people when you need them, but do the removals as a batch before your renewal date rather than one at a time.
Give them a role
Membership on its own carries no organization-level authority. Deciding who may manage members, manage repositories, see the bill, or read the audit log is a role decision — see the roles article.
Access is separate from membership
Being a member of the organization is not the same as being able to read a protected path. Membership gets someone into the repository; policy and a key grant decide what they can actually decrypt. Adding a member does not grant them anything a policy has not.