# Members & roles

Every org has exactly two roles.

## Owner

- Created automatically for whoever creates the org
- Can invite and remove members
- Can create and revoke service tokens
- Cannot see or revoke another member's personal token

## Member

- Can browse, publish, and download packages
- Gets one personal token automatically available to create
- Can see (but not create or revoke) the org's service tokens

## Inviting a member

From **Settings → Members**, enter an email address and a role. They'll get an email invite; accepting it signs them in with GitHub OAuth and adds them to the org.
