Moving Your Organization to a Team (Enterprise)
Last updated: August 22, 2026
Teams is the Enterprise workspace for Grep.ai. When your organization moves to a Team, your colleagues share one workspace, one library of agents, one billing relationship, and a set of roles that control who can build, approve, run, and share agents. Grep.ai provisions the Team for you and moves your existing work into it, so nothing you've built is lost and nobody has to start over.
This article explains what changes, what stays the same, and what happens during the migration.
Who this is for
Teams is an Enterprise feature. It is set up by Grep.ai for organizations that want:
- One shared workspace for everyone in the company
- Role-based access control over who can create, approve, run, and share agents
- A single invoice instead of individual credit cards and subscriptions
- Shared API keys that bill the organization, not the engineer who created them
If your organization isn't on a Team yet, go to Settings → Team and choose Request a team. We'll reach out to set it up, or you can book a call to expedite it.
What changes at a glance
Workspace: one shared Team workspace; what each person sees depends on their role and what's been shared with them.
Creating agents: Admins publish directly, Builders create drafts for Admin approval, Members run agents.
Sharing: Admins share agents with the whole Team or with specific teammates.
Billing: one Team account, invoiced to your organization.
API keys: Team keys bill the Team, with optional per-key spend ceilings.
Seats: no seat limit on Enterprise Teams.
Chats: still private.
How the migration works
The migration runs in stages. Grep.ai performs each stage with you, and every stage can be previewed before it's applied.
1. Your Team is provisioned
Grep.ai creates the Team with the details you agreed on:
- Team name and Team Admin (the owner)
- Email domain (for example acme.com) and whether people on that domain join automatically
- Invoice email
2. Your people join
Colleagues are added in one of two ways:
- By invitation. A Team Admin invites people by email and picks a role. Existing Grep.ai users join immediately; new users get an email with a link.
- By domain. If domain auto-join is on, everyone with your company email is enrolled, and new signups on that domain join automatically.
Joining a Team does not change anyone's login. Use the same account and the same sign-in.
3. Your existing work moves into the Team workspace
For each member, Grep.ai moves their existing work into the Team:
- Agents become Team agents and are shared with the Team, so everyone on the Team can run them.
- Runs on those agents become visible to the teammates who have access to the agent, including older runs.
- Chats never move. Conversations stay private to the person who had them, even if a chat produced a research report.
> Good to know: migration shares each migrated agent with the whole Team by default. That means every Team member, regardless of role, can run it and see its past runs. After migration, an Admin can narrow access to any agent from its Sharing tab.
4. API keys keep working
Existing personal API keys can be moved onto the Team without rotating the secret. Your integrations keep running with the same key; the only change is that usage now bills the Team and the key can read the Team's work. Scopes are never narrowed during this step.
A Team Admin can also mint new Team API keys with a chosen set of scopes and an optional lifetime spend ceiling. The key is shown once at creation, so store it then.
Two things to plan for:
- Moving a key onto the Team is one-way. Undoing it means revoking the key and issuing a new one.
- Once a member's billing is on the Team, they can no longer create personal API keys.
What stays the same
- Your login. Same account, same sign-in method.
- Your chats. Always private; never visible to the Team.
- Your integrations. Migrated keys keep the same secret.
- The product. Agents, research, and the API behave the same; only access and billing change.
Roles and permissions
Every Team member has exactly one role. Roles are managed by Team Admins under Settings → Team.
Everyone (Admin, Builder, Member)
Run agents shared with them
View runs on agents shared with them
Builder — everything above, plus:
Create agents (saved as drafts until an Admin approves them)
Admin — everything above, plus:
Create agents that go live immediately
Approve and publish drafts
Edit published Team agents
Share agents with the Team or with specific teammates
Invite members and set roles
Create and revoke Team API keys
Manage Team billing
Turn domain auto-join on or off
Owner (the primary Admin) — everything above, plus:
Cancel the Team
Notes:
Deleting (archiving) an agent is always reserved for the person who created it.
The Team owner's role can't be changed, and an Admin can't change their own role, so a Team can never lock itself out.
Who sees which runs
Visibility follows agent access, not membership alone:
- You always see your own runs.
- You see other people's runs on an agent only if that agent has been shared with you (with the whole Team, or with you specifically).
- You never see anyone else's chats.
For example, if a Builder creates a new agent after the migration and runs it before it's shared, a Member does not see that run. Once an Admin shares the agent with the Team, its runs become visible to everyone on the Team. Agents moved in by the migration are shared with the whole Team from the start, so their runs are visible to everyone unless an Admin narrows access.
Drafts and approvals
Teams add a review step so that what your organization runs has been checked by someone accountable.
1. A Builder creates or edits an agent. It is saved as a draft with the notice "A team admin must approve this agent before it goes live."
2. Drafts appear in the Team Admins' agent list under the Drafts filter. Only the Builder who wrote it and the Admins can see or run a draft.
3. An Admin reviews it and chooses Approve & publish. The agent goes live for the Team.
4. After publishing, the agent is view-only for Builders, including the one who wrote it. Further changes go through an Admin. A Builder who wants their own editable version can make a copy.
There is no "reject" button. A draft that isn't approved simply stays a draft until its creator archives it.
Sharing within a Team
Admins control who can run each Team agent from the agent's Sharing tab:
- Share with team — everyone on the Team can run the agent. They can't edit or share it.
- Share with team members — only the teammates you pick can run it. Useful for agents that a specific operator should run on the Team's behalf.
Anyone who can run a shared agent can also see the runs made on it. Chats are never included.
Frequently asked questions
Will I need to log in again or get a new account?
No. Your existing account is added to the Team.
Will my teammates see my chats?
No. Chats are never migrated, never shared, and never appear in Team views.
Will my teammates see my old research?
Only the runs on agents that are migrated and shared with them.
If a Builder runs an agent, does a Member see that run?
Only if the agent has been shared with that Member (with the whole Team or with them specifically). Otherwise, no. Note that migrated agents are shared with the whole Team by default.
Will my integrations break?
No. Existing API keys are moved with the same secret. The only behavior change is where usage is billed and which work the key can list.
Can I be on two Teams?
Each person belongs to one Team at a time.
How do I get a Team?
Go to Settings → Team → Request a team, or contact your account manager.