Members & devices
Members join your organisation by invitation (or by Microsoft auto-join), get an unmetered Reach account while they're a member, and can be removed or fully offboarded from the same screen. The Devices tab shows every machine that has signed in.
Who can manage the organisation
The person who created the organisation is its owner, and only the owner can manage it — invite and remove members, change gateways and policy, and offboard people. There is no delegated admin role yet. (TYO's own support staff can also act on an organisation when you ask for help.)
Seats live under the Settings tab (default 5). Today the seat count is what Microsoft auto-join checks before adding someone; it doesn't stop you sending invites.
Inviting a member
On the Members tab, enter an email address and click Send Invite.
- If that email already has a TYO ID, the person is added immediately — no email is sent — and their account switches to unmetered at once.
- Otherwise they receive an email with a link to
reach.tyo.com.au/invite/…, valid for 7 days. They sign in (or create a TYO ID, including with Google or Microsoft), accept, and join. Pending invites are listed under Pending Invites with a Revoke button.
Nothing needs reinstalling: the desktop client picks up group membership and policy at its next policy refresh. See Set up your team for the first-time flow.
Removing vs offboarding
Each member row has two actions:
| Action | What happens |
|---|---|
| Remove | Takes the person out of this organisation only. Their account reverts to its personal plan limits (unless they're still in another organisation). Their devices, sessions and any PCs shared with them are untouched. |
| Offboard | A one-click, organisation-wide de-provision for a leaver, run as a series of independent steps: Reach key revoked · devices marked untrusted · owned agents taken offline · Shared-PC access removed (both to and from them) · signed out everywhere · removed from this organisation. |
Use Remove for someone moving between teams; use Offboard the day someone leaves.
The Devices tab
Every time a member signs in with the desktop or mobile app, the client registers the
device. The tab lists, per device: its name (typically hostname (Platform)), the
platform (Windows, macOS, Linux, Android, iOS), the member it belongs to, and when it was
last seen. Reach keeps one row per machine — a reinstall on the same hostname updates the
existing row rather than adding a duplicate.
The list is read-only for the organisation owner. Members can review and remove their own devices from their dashboard.
Trusted devices
A device is trusted from the moment it first registers. Trust is reset to untrusted when the same machine turns up with a new device identifier (for example after a reinstall or a config reset), and for all of a member's devices when they're offboarded. Trust only matters if your access policy has Require a trusted device switched on.
Common questions
Can a member belong to several organisations?
Yes. They see the gateways and policy of each, and the strictest access policy applies. A member stays unmetered as long as they're in at least one organisation.
The invite email didn't arrive.
Check spam first. You can also send the join link yourself — it's the URL in the email — or simply create their TYO ID with them and re-send the invite: an existing account is added instantly without any email.
What does a member see after joining?
Their data cap disappears, the group's assigned gateways appear in their gateway list, and any group policy (browsers, routing rules, TCP forwards) is applied on the next refresh.
Related
- Set up your team
- SSO & MFA — enforce MFA for every member
- Access policy — restrict by country, IP, hours or device