Choose where to manage access
The steps for adding, changing, and removing access below apply to Raily-hosted sign-in.
Open the user list
- In the sidebar, go to Security and select Access.
- On the Sign-in providers tab, find the provider the person should use.
- Open the row menu. Select Manage users for Raily-hosted sign-in or View synchronized users for your own identity provider.

Each sign-in provider has its own list of users. Adding someone under one provider does not give them access to endpoints that use a different provider.
Read the user list
The three cards at the top count Direct users (managed in the Organization you have selected), Effective users (active access, direct and inherited), and Endpoints covered.
- Direct means the access was granted in the Organization you are viewing. You can change or remove it here.
- An Organization name means the access was granted higher up and is inherited. Open that Organization to change it.
- Synchronized here means the person came from your own identity provider.

Before you add a user
To add someone to a Raily-hosted sign-in, you need:- A paid plan and permission to manage users in the selected Organization. Account Owners, Administrators, and Editors have this permission, including through an inherited role.
- A Raily-hosted sign-in.
- At least one endpoint in the selected Organization that uses that sign-in.
- The email address the person will use.
Add a user
The Add user dialog takes you through Add user, Review access, and Access granted without opening another page.1
Enter the user and endpoint scope
Select Add user at the top right of the Users list. Enter the address the person will sign in with. If they use a different address later, they get no access.Pick All endpoints to cover current and future endpoints that use this sign-in in the selected Organization and its descendants, or select named endpoints from the list.
Choosing All endpoints also covers future matching endpoints in the selected Organization and its descendants. Each endpoint still has its own connect link.Select Review access. Nothing is granted yet.

2
Review and grant access
Check the Email, Organization, Sign-in, and Endpoints rows. If the person already has access through this sign-in in this Organization or one above it, the dialog marks them as an existing subscriber and says access will be added for the selected Organization.
Check the Organization carefully. An All endpoints grant covers matching endpoints in that Organization and its descendants. A named-endpoint grant stays limited to those endpoints. Neither reaches a parent Organization or a sibling.Select Grant access. Use Back if you need to change the email or endpoint scope.

3
Copy and send the connect link
After the grant succeeds, the dialog shows a Connect link for each current endpoint in the selected Organization that the direct grant covers.
Send the link to the person, or to the workspace owner or administrator who configures connectors. The link is the MCP server URL added to Claude or ChatGPT. The person signs in with the email you granted.An All endpoints grant can also cover matching endpoints in descendant Organizations. Copy those links from the descendant endpoint pages. Future matching endpoints are covered automatically, but each endpoint still has its own connect link that must be added to the AI client or workspace.

Connect to Claude
Send this to someone connecting from Claude.
Connect to ChatGPT
Send this to someone connecting from ChatGPT.
Change someone’s access
1
Open Manage access
Open the row menu on a Direct user, then select Manage access.
2
Change the endpoint selection
Choose the endpoints the person should be able to reach.

3
Save the change
Select Save. The change takes effect on the person’s next request.
Remove a user
1
Open the confirmation
Open the row menu on a Direct user, then select Remove user.
2
Confirm the removal
Check that the dialog names the correct person.
Select Remove. The person loses the direct grant on this sign-in on their next request. Their identity and any access inherited from a parent Organization are not affected.
