Users, teams and access: overview

Last updated: September 4, 2026

This page is the map for controlling who can get into your Rhythms workspace and what they can do once they are in. Everything below lives under Settings in the left navigation and is managed by Rhythms Admins. Each section says where the control is and links to the article with the steps.

Roles

Rhythms has three workspace roles: Rhythms Admin, Member and Guest. Two further labels are not workspace roles: Team Owner is a flag on a team membership and Delegate is a per-OKR role. What Members can do with organization, team and individual OKRs is set at Settings › OKRs › Permissions. See OKR roles and permissions.

Users

At Settings › Workspace › Users you invite people (individually or up to 500 at once), change roles from the Role dropdown, deactivate and reactivate accounts, and log in as a user to troubleshoot. Users are deactivated, never deleted. See Add and manage users. Anyone with invite rights can also invite a colleague by @mentioning their email in a document, comment or chat; see Invite teammates by @mention.

Guests

Guests have a view-only license: they see what is visible to them and can ask the agent questions, but cannot create, edit, comment or own OKRs. Guests count as billable seats, and converting an existing user to Guest removes their OKR ownership, so reassign first. See Guest users: read-only access.

Teams

At Settings › Workspace › Teams, Rhythms Admins create teams and Team Owners add members and create sub-teams. Team OKRs appear under the team in the left navigation. Sub-teams do not inherit settings from their parent. See Create and manage teams.

Single sign-on (SSO)

At Settings › Security, set up SSO so that everyone with your email domain signs in through your identity provider (Okta, Microsoft Entra ID and others). Rhythms matches people to accounts by email address. See Set up single sign-on (SSO).

Directory sync (SCIM) and HRIS data

Also under Settings › Security, Directory Sync connects Rhythms to your identity provider so that accounts are created when people are assigned to the Rhythms app, profile fields (name, manager, department, job title, cost center and custom fields) stay in sync, and people are deactivated when they are deprovisioned. SCIM does not assign roles or create teams; the one group it reads is the guest group, which gives its members the Guest license. Employee data can also come directly from an HRIS such as Workday through an SFTP file feed. See Set up automated user provisioning (SCIM) and HRIS integration and Set up SCIM user provisioning.

User profile attributes

Profile attributes are the organizational details attached to each person: cost center, department, division, employee type, job title and up to five custom fields, plus name and manager. They are populated by directory sync or an HRIS feed and are used in profiles, filters, columns and grouping across OKR views and reports. At Settings › Security › User Profile Attributes, a Rhythms Admin can switch each synced attribute (Cost Center, Department, Division, Employee Type, Job Title and Custom 1 to 5) on or off. Switching an attribute off hides it from profiles, filters, columns and grouping; it does not delete the stored values, and switching it back on shows them again. If an attribute you rely on is blank or stale, fix the mapping in your directory sync or HRIS feed rather than hiding it.

Billing

For workspaces created by signing up on the web, Settings › Workspace › Billing shows the plan, the seat count (active Members, Rhythms Admins and Guests), the upcoming invoice and past invoices, and links to change plan or update the payment method. Workspaces set up through the Rhythms sales team are billed under their contract and do not see this page. See Billing and subscription.

Recommended order for a new workspace

  1. Decide who your Rhythms Admins are and invite them first; keep the admin role to a small group.
  2. Set up SSO so everyone signs in with corporate credentials.
  3. Turn on directory sync so accounts, profile fields and deactivations follow your identity provider, and create the guest group if you want automatic Guests.
  4. Create teams and name their Team Owners.
  5. Review Settings › OKRs › Permissions and adjust the Create, Manage, Edit, Approve and View rows for each level.
  6. Invite or let SCIM provision the rest of the organization.

Prerequisites

  • You are a Rhythms Admin in the workspace.
  • For SSO and directory sync, you have administrator access to your identity provider.

Related articles