Skip to main content
Getting Started
4 min readUpdated 2026-02-15

Inviting Team Members

Learn how to add colleagues to your Klarvo workspace, assign appropriate roles, and establish the right permission levels for effective compliance collaboration.

Inviting Team Members

EU AI Act compliance is a team effort. System owners, oversight officers, compliance leads, DPOs, and IT admins all play distinct roles. Klarvo's team management lets you assign the right access to the right people.

How to Invite Members

  • Go to SettingsTeam (or click the Invite button in the top navigation)
  • Click Invite Member
  • Enter their work email address
  • Select a role from the dropdown (see role descriptions below)
  • Optionally add a personal message
  • Click Send Invitation
  • The invitee receives an email with a secure link to join your organization. The invitation expires after 7 days — you can resend if needed.

    Available Roles

    RoleBest ForWhat They Can Do
    AdminFounders, CTO, Head of ComplianceEverything including billing, integrations, team management
    Compliance OwnerDPO, compliance lead, legal counselAll compliance features; cannot manage billing or integrations
    System OwnerProduct managers, team leadsManage their assigned AI systems, upload evidence, complete tasks
    Reviewer/ApproverSenior compliance staff, legal reviewersReview and approve classifications, evidence, policies
    ViewerLeadership, board members, auditorsRead-only access to dashboards and reports

    See User Roles & Permissions for the complete permission matrix.

    Assigning Ownership After Invitation

    Once team members accept their invitation, you can assign them as:

  • Primary Owner: Main accountable person for an AI system — receives all related notifications and tasks
  • Backup Owner: Secondary contact when primary is unavailable — important for business continuity
  • Oversight Owner: The person with human oversight authority — must have competence, training, and authority to pause/stop the system (Article 26 requirement for high-risk deployers)
  • Privacy Owner (DPO): Linked for data governance controls and DPIA references
  • Task Assignee: Can be assigned specific compliance tasks regardless of role
  • Managing Pending Invitations

    Track outstanding invitations in Settings → Team → Pending Invitations:

  • Resend: Re-send the invitation email (resets the 7-day expiry)
  • Revoke: Cancel an invitation before it's accepted
  • Modify Role: Change the assigned role before the invitee accepts
  • Team Size Limits by Plan

    PlanUsers Included
    Free1 user
    StarterUnlimited users
    GrowthUnlimited users
    ProUnlimited users
    EnterpriseUnlimited + SSO

    Best Practices

    👥 Least privilege principle: Assign the minimum role needed — you can always upgrade later
    📧 Use work emails: Avoid personal addresses for auditability and offboarding
    🔄 Quarterly access review: Audit team membership each quarter — remove departed staff promptly
    🚪 Same-day offboarding: When someone leaves, remove their access immediately
    🏷️ Assign owners early: Every AI system should have a primary and backup owner before completing classification