Moving Your Organization to a Team (Enterprise)

Last updated: August 22, 2026

Teams is the Enterprise workspace for Grep.ai. When your organization moves to a Team, your colleagues share one workspace, one library of agents, one billing relationship, and a set of roles that control who can build, approve, run, and share agents. Grep.ai provisions the Team for you and moves your existing work into it, so nothing you've built is lost and nobody has to start over.

This article explains what changes, what stays the same, and what happens during the migration.

Who this is for

Teams is an Enterprise feature. It is set up by Grep.ai for organizations that want:

- One shared workspace for everyone in the company

- Role-based access control over who can create, approve, run, and share agents

- A single invoice instead of individual credit cards and subscriptions

- Shared API keys that bill the organization, not the engineer who created them

If your organization isn't on a Team yet, go to Settings → Team and choose Request a team. We'll reach out to set it up, or you can book a call to expedite it.

What changes at a glance

  • Workspace: one shared Team workspace; what each person sees depends on their role and what's been shared with them.

  • Creating agents: Admins publish directly, Builders create drafts for Admin approval, Members run agents.

  • Sharing: Admins share agents with the whole Team or with specific teammates.

  • Billing: one Team account, invoiced to your organization.

  • API keys: Team keys bill the Team, with optional per-key spend ceilings.

  • Seats: no seat limit on Enterprise Teams.

  • Chats: still private.

How the migration works

The migration runs in stages. Grep.ai performs each stage with you, and every stage can be previewed before it's applied.

1. Your Team is provisioned

Grep.ai creates the Team with the details you agreed on:

- Team name and Team Admin (the owner)

- Email domain (for example acme.com) and whether people on that domain join automatically

- Invoice email

2. Your people join

Colleagues are added in one of two ways:

- By invitation. A Team Admin invites people by email and picks a role. Existing Grep.ai users join immediately; new users get an email with a link.

- By domain. If domain auto-join is on, everyone with your company email is enrolled, and new signups on that domain join automatically.

Joining a Team does not change anyone's login. Use the same account and the same sign-in.

3. Your existing work moves into the Team workspace

For each member, Grep.ai moves their existing work into the Team:

- Agents become Team agents and are shared with the Team, so everyone on the Team can run them.

- Runs on those agents become visible to the teammates who have access to the agent, including older runs.

- Chats never move. Conversations stay private to the person who had them, even if a chat produced a research report.

> Good to know: migration shares each migrated agent with the whole Team by default. That means every Team member, regardless of role, can run it and see its past runs. After migration, an Admin can narrow access to any agent from its Sharing tab.

4. API keys keep working

Existing personal API keys can be moved onto the Team without rotating the secret. Your integrations keep running with the same key; the only change is that usage now bills the Team and the key can read the Team's work. Scopes are never narrowed during this step.

A Team Admin can also mint new Team API keys with a chosen set of scopes and an optional lifetime spend ceiling. The key is shown once at creation, so store it then.

Two things to plan for:

- Moving a key onto the Team is one-way. Undoing it means revoking the key and issuing a new one.

- Once a member's billing is on the Team, they can no longer create personal API keys.

What stays the same

- Your login. Same account, same sign-in method.

- Your chats. Always private; never visible to the Team.

- Your integrations. Migrated keys keep the same secret.

- The product. Agents, research, and the API behave the same; only access and billing change.

Roles and permissions

Every Team member has exactly one role. Roles are managed by Team Admins under Settings → Team.

Everyone (Admin, Builder, Member)

  • Run agents shared with them

  • View runs on agents shared with them

Builder — everything above, plus:

  • Create agents (saved as drafts until an Admin approves them)

Admin — everything above, plus:

  • Create agents that go live immediately

  • Approve and publish drafts

  • Edit published Team agents

  • Share agents with the Team or with specific teammates

  • Invite members and set roles

  • Create and revoke Team API keys

  • Manage Team billing

  • Turn domain auto-join on or off

Owner (the primary Admin) — everything above, plus:

  • Cancel the Team

Notes:

  • Deleting (archiving) an agent is always reserved for the person who created it.

  • The Team owner's role can't be changed, and an Admin can't change their own role, so a Team can never lock itself out.

Who sees which runs

Visibility follows agent access, not membership alone:

- You always see your own runs.

- You see other people's runs on an agent only if that agent has been shared with you (with the whole Team, or with you specifically).

- You never see anyone else's chats.

For example, if a Builder creates a new agent after the migration and runs it before it's shared, a Member does not see that run. Once an Admin shares the agent with the Team, its runs become visible to everyone on the Team. Agents moved in by the migration are shared with the whole Team from the start, so their runs are visible to everyone unless an Admin narrows access.

Drafts and approvals

Teams add a review step so that what your organization runs has been checked by someone accountable.

1. A Builder creates or edits an agent. It is saved as a draft with the notice "A team admin must approve this agent before it goes live."

2. Drafts appear in the Team Admins' agent list under the Drafts filter. Only the Builder who wrote it and the Admins can see or run a draft.

3. An Admin reviews it and chooses Approve & publish. The agent goes live for the Team.

4. After publishing, the agent is view-only for Builders, including the one who wrote it. Further changes go through an Admin. A Builder who wants their own editable version can make a copy.

There is no "reject" button. A draft that isn't approved simply stays a draft until its creator archives it.

Sharing within a Team

Admins control who can run each Team agent from the agent's Sharing tab:

- Share with team — everyone on the Team can run the agent. They can't edit or share it.

- Share with team members — only the teammates you pick can run it. Useful for agents that a specific operator should run on the Team's behalf.

Anyone who can run a shared agent can also see the runs made on it. Chats are never included.

Frequently asked questions

Will I need to log in again or get a new account?

No. Your existing account is added to the Team.

Will my teammates see my chats?

No. Chats are never migrated, never shared, and never appear in Team views.

Will my teammates see my old research?

Only the runs on agents that are migrated and shared with them.

If a Builder runs an agent, does a Member see that run?

Only if the agent has been shared with that Member (with the whole Team or with them specifically). Otherwise, no. Note that migrated agents are shared with the whole Team by default.

Will my integrations break?

No. Existing API keys are moved with the same secret. The only behavior change is where usage is billed and which work the key can list.

Can I be on two Teams?

Each person belongs to one Team at a time.

How do I get a Team?

Go to Settings → Team → Request a team, or contact your account manager.