# Admin settings and controls

As a Business Edition admin, you control who's in your workspace, what data CTD can access, which integrations are live, and how your team sends outreach. This article is a map of every admin control and where to find it.

## Where admin settings live

All admin controls live under **Settings** in the left sidebar. Admin-only sections are visible only to users with the **Admin** role — regular members won't see them. The Settings sidebar is grouped into:

- **Admin settings** — Technical setup, Implementation, Outreach, Privacy, MCP
- **CRM Integration** — Salesforce, HubSpot
- **User Management** and **External members**
- **Billing** — Subscription, Plans & Pricing
- **Personal settings** — your own Sharing & Privacy, LinkedIn import, Templates, Signatures, and more

The **Admin Dashboard** (also linked from the main sidebar) is your at-a-glance view of setup progress, network growth, and adoption across the org.

## User management

Open **User Management** to manage everyone in your workspace. Users are split across three tabs:

| Tab | Who's here |
| --- | --- |
| **Licensed users** | Team members with an active license connected to your workspace. |
| **Unlicensed users** | Users discovered in your domain who haven't been activated, or were previously deactivated. |
| **Legacy Users** | Accounts that still exist in CTD but have been removed from your enterprise directory. |

The seats counter at the top shows **{used} / {purchased} seats used**. When all seats are taken, use **Increase Seats** (or the Billing section) to add more before inviting.

### Walkthrough: managing users

Scribe | Embed Managing_Users__PlcJF8OkTpSK8Z9D_6w4Uw

# Managing Users

Learn how to efficiently manage your workspace settings and user access levels. This guide walks you through navigating account details to adjust team permissions and organize member categories.

5 Steps  
28 seconds

### Adding and inviting users

Use **Add user** to add up to 100 email addresses at once. There's an optional **Skip syncing contacts** option — when enabled, those users are added to the workspace but their email is not synced (useful when you want someone in the org without processing their inbox).

New CTD users appearing in your domain can be brought in automatically with the **Auto-Add CTD users** toggle — it adds all new CTD users from your domain to the company network. Leave it off if you'd rather add people manually.

### Roles and permissions

CTD has two roles: **Admin** and member. Admins are marked with an **Admin** badge in the users table. From a user's row menu (or via bulk selection) you can:

- **Make admin** / **Remove admin** — grant or revoke admin access
- **Deactivate** — downgrade a user to the CTD free edition, removing them from your company network and enterprise features like Paths
- **Activate** — restore a deactivated user
- **Delete** — permanently remove an email account and all contact data tied to it (requires typing `DELETE` to confirm)
- **Send email** — send a reminder/nudge to a user

**You can't remove your last admin.** CTD blocks removing the final admin on the account, so there's always someone who can manage the workspace. If you're handing off ownership, promote the new admin before removing yourself.

### Connector controls per user

Two per-user settings shape how your team appears in the Paths report:

- **Show in Paths** — show or hide a user as a connector. Your team can't send asks to connectors that are hidden.
- **Tier** — each connector's tier (1 = high, 4 = low) determines how strongly they're recommended in the Paths report.

## Data access controls

Beyond who's in the workspace, you control what CTD and connected tools can _do_ with your data.

### Email access scope

How much of company email CTD reads is set at rollout via domain-wide delegation — from metadata-only up to full read-and-send. This is the single biggest data-access decision. See [Email access & permissions](/content/guide/article/business-email-permissions/index.html) for the four scopes and what each unlocks.

### MCP write policy

Under **Settings → MCP**, the **Forbid write access via MCP** control governs what members can do through the CTD MCP integration (Claude, Cursor). When enabled:

Members keep **read** access — viewing their network, paths, contacts, companies, and job changes — but lose **write** access, meaning they can't send ghost emails, create lists, change path stages, or make other changes via MCP. Members can't override this; only an admin can change it here. See [MCP overview](/content/guide/article/mcp-overview/index.html) for the full picture.

### Workspace privacy & sharing

Individual users control their own network visibility under their personal **Sharing & Privacy** settings, and admins can hide any connector from Paths (above). Workspace-wide privacy defaults — org-level open/closed network rules with block and whitelist controls — are on the roadmap and appear under **Settings → Privacy**.

## Integrations

### CRM integration

Open **Settings → CRM Integration** to connect your CRM. CTD supports **Salesforce** today, with HubSpot coming soon. One CRM is connected per workspace. Setup runs in three steps:

- **Authorize** — connect your CRM account so CTD can read and write data
- **Pull rules** — what CTD reads from your CRM (e.g. syncing Accounts, filtering target accounts by CRM fields)
- **Push rules** — what CTD writes back to your CRM records (relationship insights, warm path counts, and more)

For step-by-step instructions, see [Salesforce integration](/content/guide/article/crm-salesforce/index.html) and [HubSpot integration](/content/guide/article/crm-hubspot/index.html).

### Technical setup

**Settings → Technical setup** walks you through getting your workspace ready, with a completion percentage so you can track progress. Steps include installing the CTD iFrame inside Salesforce or HubSpot (embedding Paths directly in your CRM), defining target accounts (via CRM sync or a CSV upload), setting target personas, and installing the Chrome extension. Each step has a status you can set to Not started, In progress, Done, or Skipped.

### API keys

Under **Settings → API keys** there are two types:

- **Personal API key** — programmatic access to an individual's own network.
- **Enterprise API key** — admin-only access built for internal tools, not intended for individual use. Only admins can create these; each shows who created it. Revoking a key is permanent.

See [API overview](/content/guide/article/api-overview/index.html) for how to use them.

## Outreach and approvals

Under **Settings → Outreach** you manage how your team reaches out:

- **Outreach approvers** — add an approval layer for introduction requests, set default approvers for both enterprise users and external members, add individual overrides, and optionally enforce approvals so users can't go directly to a connector.
- **Email templates** — customize the enterprise email templates your team uses.

Approvals have their own detailed walkthrough — see [Configuring outreach approvers](/content/guide/article/business-outreach-approvers/index.html) and [Email and intro templates](/content/guide/article/business-templates/index.html).

## External members

The **External members** page (admins only) manages people outside your company — investors, advisors, and board members — whose networks contribute to your paths. Tabs cover All members, Accepted, Pending, Waiting for approval, and Declined invites. From here you can invite external members, approve requests, set their connector tier, and remove members. See [External members overview](/content/guide/article/external-members-overview/index.html).

## Monitoring adoption

The **Admin Dashboard** pulls the above together: technical setup progress, network growth over time, external member counts (accepted and pending), and prompts to grow your network both externally and from within. Check it periodically to spot users who haven't activated, stalled integrations, or setup steps still outstanding.

**Setting up for the first time?** Work through the [Implementation checklist](/content/guide/article/business-implementation/index.html) — it sequences these controls in the right order for a smooth rollout.

Have a question or running into an issue? Email us at [support@ctd.ai](mailto:support@ctd.ai) — we're happy to help.
