For Teams
Cursor Team Members, Roles & Seat Types (Admin Guide)
Cursor Teams separate roles (who can administer) from seat types (how much usage is included). Members and Admins need a paid Standard ($40/mo) or Premium ($120/mo, 5× usage) seat; Unpaid Admins manage billing and security without consuming a license. Add people by email invite, share link, SSO or domain matching; removing a member deletes their Memories and Cloud Agent data permanently.
On this page
What roles exist on a Cursor team?
Three roles answer one question: who can administer the team. Members and Admins both get full product access, and the difference is what they can change. Unpaid Admin is the outlier, with admin controls but no paid seat.
- Role
- Member
- Product access
- Full Pro features
- Admin capabilities
- Invite members; set personal usage limits
- Role
- Admin
- Product access
- Full Pro features
- Admin capabilities
- Billing, SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition., analytics, member management
- Role
- Unpaid Admin
- Product access
- None (no paid seat)
- Admin capabilities
- Same admin controls as Admin without a license
| Role | Product access | Admin capabilities |
|---|---|---|
| Member | Full Pro features | Invite members; set personal usage limits |
| Admin | Full Pro features | Billing, SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition., analytics, member management |
| Unpaid Admin | None (no paid seat) | Same admin controls as Admin without a license |
Every team needs at least one Admin and one paid member.
Unpaid Admin is the pattern for IT, security or finance staff who configure SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. and spend caps but do not write code in Cursor. They do not count toward billable seats.
The role question that actually comes up is who gets Admin, and the honest answer is fewer people than ask for it. Admin bundles billing, SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition., member management and analytics together, which is a strange combination in practice: the person who should be watching spend is rarely the person who should be editing your SAMLSecurity Assertion Markup Language. The XML-era enterprise standard that powers single sign-on: your identity provider vouches for you to each app. Older than OIDC but still what many enterprise tools speak. Press Enter for the full definition. configuration. Cursor does not split those capabilities, so the only control you have is how many people hold the role.
Unpaid Admin covers the other half of that problem, and it turns out to be the cleanest way to handle it. Same administrative capabilities, no product access, no seat cost, so IT and finance hold the controls they need without a $40 line each. It cannot cover everyone, though: one paid member always has to remain, so the last paid seat is not convertible.
This is covered hands-on in Teams and Enterprise Admin — 6 short modules, free to read.
What is the difference between Standard and Premium seats?
A seat type sets how much included usage someone gets, separate from their role. Standard covers most engineers; Premium is for the few who routinely run out, with 5x the usage. Unpaid Admin sits outside both, with no product access.
- Standard
- $40/user/mo with the default Teams usage allowance.
- Premium
- $120/user/mo with 5× the included usage of Standard.
- Unpaid Admin
- Free admin-only seat; no product access or included usage.
Seat type is independent of role: a Member or Admin can hold either Standard or Premium. Admins upgrade or downgrade seat type from the member context menu. Upgrades apply immediately with pro-rated billing; downgrades take effect at the next renewal while the user keeps Premium through the current cycle.
Seat type is also the decision most often made wrong in advance. Premium carries 5x the included usage at three times the price, so it pays for itself only for people who genuinely exhaust the Standard allowance, and I suspect that group is smaller than the number of people who ask. You cannot know who is who before there is usage data, and the upgrade path is short: immediate, pro-rated, done from the member menu.
The default should be Standard for everyone, including the people who insist otherwise.
Downgrades run the other way and the asymmetry is worth planning around. A downgrade lands at the next renewal and the person keeps Premium for the rest of the cycle, so a mid-cycle correction never shows up on this month's invoice. If you are trimming to hit a number this month, neither downgrades nor removals will do it: a removed member who used any credits keeps their seat until the period ends as well.
How do we add and remove team members?
There are four ways to add people, from a one-off email invite up to SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. and domain matching that let teammates join on their own. Which one you reach for depends on how much you want to manage by hand. Removal happens from the member context menu, and it is permanent for that person's data.
- 1Email invite: click Invite Members and enter addresses; users receive email links.
- 2Invite link: copy a shareable link from the same dialog (revoke regularly or prefer SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition.).
- 3SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition.: users auto-join when they sign in with a configured SAMLSecurity Assertion Markup Language. The XML-era enterprise standard that powers single sign-on: your identity provider vouches for you to each app. Older than OIDC but still what many enterprise tools speak. Press Enter for the full definition. identity provider.
- 4Domain matching: with a verified domain, teammates can join from the dashboard without a direct invite.
The four methods differ mostly in how much you trust the boundary. An email invite is explicit and slow. A shareable link is fast, lives a long time and lets in whoever has it, which makes it the one to revoke on a schedule instead of leaving it in a Slack channel from March. SSOSingle Sign-On. One company login (usually via SAML or OIDC) instead of a separate password per tool. Press Enter for the full definition. and domain matching move the boundary out to your identity provider or your verified domain, which is where it belongs once the team is past a few dozen people.
Admins remove members from the context menu. If the member consumed any credits, their seat stays occupied until the billing period ends; billing adjusts with pro-rated credit on the next invoice. Removed users lose Memories and Cloud Agent data permanently.
That last sentence is the part to read twice. There is no export step and nothing to restore from afterwards, so when a departing engineer leaves behind a cloud agent history somebody else will need, pull it before the removal goes through rather than after. The billing side looks after itself.
When should we use domain matching vs SCIM?
Domain matching and invite-domain restrictions are for Teams that manage membership inside Cursor. Domain matching lets anyone with a verified company email self-join; restrict invites to verified domains blocks invitations outside your domains. If you use SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. on Enterprise, membership flows from your identity provider instead and these manual domain controls are superseded.
The part of SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition. that belongs on this page rather than the provisioning one is roles, because SCIM does not map them. Everyone arrives as a Member, so promoting an Admin stays a manual step in the Cursor dashboard even when membership is entirely automated. Teams that assume the identity provider carries the whole picture discover this the first time an admin leaves and nobody left can reach the billing settings.
Both domain controls need at least one verified domain, and both are available only while you are not provisioning through SCIMSystem for Cross-domain Identity Management. A standard for automatically creating and removing user accounts when people join or leave. Press Enter for the full definition.. Which is the right way round. Once the directory owns membership, leave the domain toggles off so there is exactly one way in.
Frequently asked questions
Can an Admin use Cursor without paying for themselves?
Only if they switch to Unpaid Admin, which removes product access. The team still needs at least one paid member besides unpaid admins.
What happens to a developer's data when we offboard them?
Cursor permanently deletes their Memories and Cloud Agent data when they are removed from the team. Plan offboarding accordingly.
How do we give power users more included usage?
Upgrade their seat from Standard to Premium in the member menu. Premium includes 5× the Standard usage pools.
Sources & last verified
Cursor ships frequently. Last updated July 28, 2026.
Keep reading
Rather do it than read about it? Run 11 interactive Cursor walkthroughs in a simulated editor. Free, no account needed.