# Overview (/en/docs/platform/team)



Managing who works in CentralCSP happens in two places, because there are two role systems.

**Team** manages workspace membership: who belongs, and who administers the account.

On a website, **Settings** > **Access control** manages what someone can do on that site.

## What you can do [#what-you-can-do]

Five pages cover the two role systems between them:

* **Invite and manage members:** Add people, set their workspace role, remove them. [Members](/en/docs/platform/team/members)
* **Track invitations:** Statuses, the 7-day expiry, and why revoking matters. [Invitations](/en/docs/platform/team/invitations)
* **Bundle people into groups:** Grant website access once instead of per person. [Groups](/en/docs/platform/team/groups)
* **Grant website access:** Per site, to people or groups. [Website access](/en/docs/platform/team/website-access)
* **Understand the roles:** Both systems and how they interact. [Roles and permissions](/en/docs/platform/team/roles-and-permissions)

## Set up a new team [#set-up-a-new-team]

Work through these four steps in order:

1. **Invite everyone as Member.** Reserve Admin for the small number of people who administer the account, since Admins reach every website automatically and cannot be restricted.
2. **Create a group per delivery team**, plus one for security or compliance.
3. **Grant each group a role per website.** Manager on the sites the team owns, Viewer elsewhere.
4. **Give script reviewers Analyst** on payment-facing sites, so they can justify and reject without being able to change scope.

After that, onboarding is one action: add the person to their group.

## Next steps [#next-steps]

* [Roles and permissions](/en/docs/platform/team/roles-and-permissions)
* [Members](/en/docs/platform/team/members)
* [Groups](/en/docs/platform/team/groups)
