# Team hub

> The home page of a team workspace: what needs you, who is around, who is carrying what, who can open which board, and what changed while you were away.

**Team** at the top of the sidebar opens the hub of a team workspace. It is seven
tabs, each a real address you can bookmark or send to someone.

| Tab      | What it answers                                                            |
| -------- | -------------------------------------------------------------------------- |
| Overview | What needs me today, and who is around                                     |
| People   | Who is here, in what role, and who is still invited                        |
| Workload | Who is carrying what, across every board at once                           |
| Agents   | The team's own agents and their runs, then decisions, pacts and assistants |
| Access   | Who can open which board                                                   |
| Activity | What changed, and who changed it                                           |
| Security | Sign-ins, access changes and exports, on a record nobody can edit          |

Everything reads from the same live data as the rest of the app, so a card
moved on someone else's laptop shows up without a refresh.

## Overview

The top of the page is one list called Needs attention, ordered by how stuck
each thing is:

1. Decisions an agent is waiting on. Work has stopped until someone answers.
2. Overdue cards.
3. Boards nobody can open any more.
4. Open cards nobody owns.
5. Boards only one person can open.
6. Invitations still waiting for an answer.

A row only appears when its count is more than zero, and when the list is empty
it says so. Rows 3, 5 and 6 are for owners and admins, so a member sees a
shorter list with no "not allowed" message in it.

On a wide screen the Overview is two columns. The main column holds Needs
attention, then the **Agents** strip and, for owners and admins, the **Admin
console** and **Assistant use and caps**. The narrower column on the right is
about the team:

- the faces of the team, with who is in the app right now said in words as
  well as dots;
- **Invite someone to the team**, for owners and admins, which
  opens People;
- **Everything this team runs on**, a list of the team's own pages (shared boards,
  Workload, People & roles, Who can open what, Assistants & pacts, outside
  assistants, webhooks, Activity and Security). A page your plan does not include stays
  in the list, locked, and names the plan that has it.

On a phone, or a narrow window, it is one column in this order: Needs
attention, the welcome (if you have one), the main column, then the team.

> **Side note:** In your first two weeks on a team a welcome waits at the top of the right-hand
> column: who is here, what you can already open, and who to ask if the answer is
> nothing.

## People and roles

- **Owner**: runs the workspace, holds the plan, and is the only person who can delete it
  or hand it over.
- **Admin**: invites, removes and re-roles people and edits workspace settings. Not
  billing.
- **Member**: sees everything shared in the workspace and makes their own boards, notes
  and lists.

People lists everyone with their presence, the roles you are allowed to change,
open invitations you can revoke, and ownership handover. When a button is not
yours to press, the page says which role it belongs to.

Board roles (owner, editor, viewer) sit on top of these, board by board. See
[Sharing and permissions](https://themarginapp.com/docs/sharing-and-permissions).

## Workload

Workload counts open cards, overdue cards, cards due in the next seven days and
cards nobody owns, then lets you look **By person**, **Unassigned**,
**Overdue** or **Due in 7 days**. It reads the local database, so it works
offline and moves the moment anyone drags a card.

Switch from **List** to **Timeline** to see the same cards on a calendar. Each
person gets a row and each day of this week (or this month) gets a column, with
every card on the day it is due, so a pile-up on one day stands out. Late cards
sit together in an **Overdue** column at the front, today is marked, and
anything with no date or due later is counted beside the person's name. A week
fits a wide screen; a month, or any view on a narrow screen, scrolls sideways and
opens with today in view. Click a card to open it. In the phone app the timeline reads down instead of across: overdue
first, then each day that has something due, with the person named on every
card. The page remembers which layout you picked.

> **Known limit: Only the boards you can open** Workload covers the boards you are on, not every board in the workspace. The
> page says so under its header and links to Access, where an admin can see
> the rest.

## Access

Creating a board puts one person on it: whoever made it. In a team workspace
that makes every new board private until someone shares it, and when a person
leaves, the boards only they were on can end up with nobody at all.

Access is for owners and admins, and it shows every board in the workspace
whether or not you are on it. Filter to **Only one person**, **Nobody** or
**Shared outside**, then add people, change their board role or remove them in
place.

### Guests

A guest is someone outside the workspace who can open a board, note,
whiteboard or checklist you shared with them, as a viewer or an editor, and
nothing else. A client on one board, a contractor on two notes. Guests are
free: they never take a seat, they cannot invite anyone, and their devices
receive only what was shared with them. A Team workspace can have up to 50.

You add a guest the same way you share anything, from the board's or the
note's share dialog. The **Guests** list at the bottom of Access shows every
outside person at once and what each can open, and **Remove** takes all of
someone's access in this workspace away in one step. A board they still own
keeps its owner.

### Company sign-in

Owners and admins can require every member to sign in with a Google account on
the company's domain, under **Sign-in** at the bottom of Access. Type the
domain, such as `acme.com`, and choose **Require Google sign-in**.

- You can only pick a domain you sign in with yourself, through Google, so the
  rule cannot lock you out.
- If any member's address is on another domain, it will not turn on, and you
  are told who. Change their address or remove them first.
- New invitations only go to addresses on the domain. Guests are not affected:
  they are outside the workspace by definition.
- Anyone signed in another way, such as with an email link, keeps their account,
  but the workspace stops opening and syncing for them until they sign in with
  Google on the domain. Their workspace list shows it as **Sign in with Google
  (@acme.com) to open**.
- Accepting an invitation asks for the same sign-in. An invitation link opened
  from an email-link session goes to Google sign-in first and finishes on its
  own afterwards.
- The phone app and any assistant you connect over MCP follow the same rule:
  a connection approved from another kind of sign-in loses the workspace until
  it is connected again after signing in with Google. Margin Intelligence won't
  start a conversation in a workspace your sign-in can't open, or reach into
  one from a conversation somewhere else.
- Changes made offline on a device that no longer meets the rule are not
  saved to the workspace when it reconnects. Sign in with Google on the domain
  and make them again.
- A member who is already in a live board or note when the rule turns on
  leaves it within a few seconds if their sign-in doesn't meet the rule.
  Everyone else stays in.

Turning it off takes effect at once. On the phone, the setting is shown on the
Team access screen and changed on the web. Single sign-on through SAML and
automatic provisioning (SCIM) are not part of Team; they are planned for a
later enterprise plan. Today a Team can require Google sign-in on its domain
and two-factor for every member.

### Two-factor for every member

Under **Two-factor sign-in** on Access, owners and admins can require every
member to use an authenticator app when they sign in. See
[Two-factor sign-in](https://themarginapp.com/docs/two-factor-sign-in) for how a person sets it up.

- Turn on two-factor for your own account first. The rule won't turn on from
  an account without it, so it can't lock you out.
- Before it turns on, you see who doesn't have two-factor yet. They are not
  removed. They keep their place, but the workspace won't open or sync for
  them until they turn it on, and their workspace list says **Turn on
  two-factor to open**.
- Held means closed: the workspace stops opening and syncing for them, and
  its copy leaves their devices the next time they are online.
- A held member who has a board or note open with others drops out of its
  live presence and shared editing within a few seconds.
- It holds members only. Guests see only the boards and items you share with
  them and are not held; household profiles never sign in, so they are not
  held either.
- A member who loses their phone signs in with a recovery code. There is no
  admin reset yet; a member with no codes left writes to support, who check it
  is really them first.
- The phone app, Margin Intelligence and assistants connected over MCP follow
  it too: none of them reaches the workspace for a held member. In the phone
  app the same switch is on **Team → Access**, with the same check first.
- Turning it on or off, and every member's two-factor changes, are written to
  the security log.

Turning it off takes effect at once and frees everyone it was holding.

## Assistant use and caps

A Team's assistant allowance is one shared pool, 600 actions for each seat.
Without a ceiling, one busy person can use the whole month. **Assistant use and
caps** on the hub's front page, for owners and admins, shows the pool first:
how many actions the team has used this month out of how many, and how many
are left. Under it, each person's actions this month, their share of the pool
and, when they have one, a bar against their cap. Spend no listed person
accounts for, such as a scheduled agent's runs or someone who has since left,
is counted under the pool so the numbers add up. The month is the calendar
month in UTC, the same one the assistant counts.

Owners and admins can give any member a monthly cap in the same list. When someone
reaches their cap, the assistant tells them their admin set it and that it
resets on the 1st; purchased credits do not lift it. Nobody has a cap until one
is set, and the owner is never capped. Every change is in Activity and in the security log.

## Activity

The full trail, with a person's name on every row. It includes the governance
events too: invitations, removals, role changes and board access. So "who
removed Maya?" has an answer. An event whose subject has since been deleted
drops out rather than pointing at nothing.

## Security

**Security** is the workspace's security log, for owners and admins. It records:

- sign-ins and two-factor changes for everyone in the workspace, including a
  wrong code and a recovery code used;
- invitations, people joining, leaving and being removed, role changes and
  ownership handover;
- board access granted, changed or removed, board share links, and every note,
  whiteboard or checklist shared or unshared, marked when the person is from
  outside the workspace;
- the company sign-in rule, two-factor requirements and assistant caps;
- every download of this log and of the whole workspace.

Filter by **Sign-in**, **People**, **Access and sharing**, **Policies** or
**Exports**, or by person (it shows what they did and what was done to them).
Each entry has a number, a time and the network it came from. Only the first
three parts of an address are kept, never the full address.

Nobody can edit or delete an entry, owners included. Each entry carries a
fingerprint of itself and of the one before it, worked out by the database as
it is written. **Chain verified** at the top means every entry still matches;
if one was ever changed, the page names the first that does not. The last
entry's number and fingerprint are shown there and travel in every download,
so a copy you keep can later prove nothing up to that point changed. Entries
are kept for as long as the workspace exists; deleting the workspace deletes
its log.

**Log as CSV** and **Log as JSON** download
the whole log, up to ten times an hour.

### Export everything

**Download the zip** builds one zip of the whole workspace on
our servers, including boards you are not on: boards, columns, cards, assignees,
labels, comments, checklists, notes, folders and whiteboards, plus members and
their roles (and whether each has two-factor on), guests, invitations, share
links, the company sign-in rule, two-factor requirements, assistant caps and the
security log. Every file comes as JSON and as CSV, with a `manifest.json` and a
`README.txt` that list what is inside.

Left out on purpose: anyone's assistant conversations, expenses, income and
focus sessions (an admin does not see those in the app either), PIN hashes,
invitation and share-link tokens, payment ids, attached files, and the contents of PIN-locked boards and notes, which are
listed and marked locked so their owner can unlock and export them. Each kind of
thing stops at 50,000 rows and the whole zip at 150 MB; anything cut short is
named in the manifest. A workspace can be exported three times an hour, and
every export is in the security log. Your own data from every workspace is a
different download, described in [Your data](https://themarginapp.com/docs/your-data).

## Agents

The team's own agents come first: one card each, with its schedule in words,
when it runs next, **Run now** and its last result, plus
**New agent** and three starters. Below them, the recent runs,
each opening to its result. See [Team agents](https://themarginapp.com/docs/team-agents).

Then what your other agents are doing, written for someone who has never heard
of MCP: decisions waiting on a person, the pacts in force, and the assistants
connected to this workspace. Two doors start things: **Start a pact**
and **Connect an assistant**. See [Agent pacts](https://themarginapp.com/docs/agent-pacts).

## Seats

Team is billed per seat, starting from one, and seats are checked against what
was bought. When the workspace is full, the next invitation is refused with a
sentence saying why and an **Add a seat** button that opens the seat count on
the **People** tab with one more seat filled in.

- A seat is a person, counted across all the team workspaces one owner holds.
  The same colleague in two of your team workspaces is one seat.
- An open invitation holds a seat until it is answered or expires. That
  includes an invitation to an address with no account yet, so you can't send
  more invitations than you have seats.
- A trial started in a team workspace holds up to 5 people.

### Adding and removing seats

The owner changes the seat count at the top of **People**, in
**Settings → Billing**, or from the seats tile in the admin
console: press plus or minus, check the new total and the price per seat, then
Confirm. You can set anything from 1 to 500 seats there. For more, write to us.

A change is prorated. Seats you add are charged for the rest of the current
billing period on your next invoice, and seats you remove come back as a
credit on it. Nothing is taken from your card when you click.

You can't go below the people who hold a seat, open invitations included.
Removing a member frees their seat but does not lower the bill. To pay for
fewer seats, remove the person (or cancel the invitation) and then lower the
count.

The phone app shows how many seats are in use. Seats are managed on
themarginapp.com.

The admin console on the Overview shows seats used against seats bought,
AI actions used this month, and the audit log, with a CSV export.
Only owners and admins see it.

## Ask the assistant

Margin Intelligence, and any assistant you connect over MCP, can read the hub
for you. Anyone in the workspace can ask who is on the team and who is
carrying what. Owners and admins can also ask:

- what changed and who changed it, from the same trail as **Activity**, a page
  at a time, or only the membership and access changes;
- who can open which board, including boards only their creator can open,
  boards nobody can open any more, and people from outside the workspace;
- how many seats are bought and held, open invitations included, and how many
  assistant actions the team and each person have used this month, with their
  cap if one is set;
- the security log, a page at a time, by group or person, with whether the
  chain verifies.

A member who asks gets told it is for owners and admins. The assistant only
reads here. Inviting, removing, changing roles, board access and seats stay in
the app, done by a person.

## Who gets it

The hub is for team workspaces, and for shared ones, on the Team plan. The
**Team** row only appears in the sidebar where it applies.

- Opened by address from a personal or family workspace, the page explains that
  the hub belongs to team workspaces and links to **Workspace settings**,
  where you can change the type.
- In a team workspace without the plan, you get one upgrade prompt instead of a
  page of buttons that fail.

> **On the phone:** The phone app has Overview, People, Workload, Access and Activity, laid out as
> lists, and the team's agents: list, make, run and read results. Owners and
> admins find the downloads at the end of Access: the whole workspace as a zip,
> and the log as CSV or JSON, saved through the share sheet on iPhone or into a
> folder you pick on Android. Each one is written to the log, as on the web.
> Pacts, the decision inbox and the log's own page are on the web.

> **Note: A household wants a family workspace** Chores, pocket money and the House Cup are the family suite, which Team does
> not include. See [Family workspaces](https://themarginapp.com/docs/family).

**Where to next**

- [Sharing and permissions](https://themarginapp.com/docs/sharing-and-permissions): board roles and invite links
- [Agent pacts](https://themarginapp.com/docs/agent-pacts): several agents on one job, under rules the server enforces
- [Team agents](https://themarginapp.com/docs/team-agents): agents the team makes for itself, on demand or on a schedule
- [Plans and limits](https://themarginapp.com/docs/plans-and-limits): what Team includes and what the trial grants


---

Section: Together. Checked against the running product on October 5, 2026.
Web page: https://themarginapp.com/docs/team-hub. Every docs page: https://themarginapp.com/docs/llms.txt
