Team and access
Team members
Give other people their own login into your workspace, with a role that limits what they can touch.
Sharing one login is how you end up unable to answer "who restarted the server?". Instead, create a login for each person. They sign in with their own password, and their role decides what they may do.
The common case: a business owner adds their servers, then creates a login for the DevOps engineer they hired. The engineer can work on the servers and in chat, and cannot add, edit or delete anything the owner owns.
Requirements
Team logins need the Team plan, and you must be an Owner or Admin to manage them. On other plans the Team tab does not appear. See Plans.
Up to 6 logins are included.
Pages here
- Roles — what Owner, Admin, Operator and Viewer can each do. Read this before adding anyone.
- Add a member — the dialog, and what to send them.
- Signing in as a team member — send this page to the person you just added.
How it fits together
- Your workspace owns everything: projects, servers, integrations, AI credit.
- Your workspace has a 12-digit Account ID, shown in Settings → Account.
- A member signs in with Account ID + email + password on the Team member tab.
- A member owns nothing. They work inside your workspace, within their role, and optionally only on the projects you choose.
Shared and pooled
- Integrations are shared. Jenkins, Jira, Grafana, MCP and MySQL connections are visible to everyone who can see their project.
- AI credit is pooled — everyone spends from the owner's balance. Per-person credit would block the junior engineer at the worst possible moment.
- Chats and notes are private to each person.
One person, several logins
The same email address can hold a personal account and be a member of several workspaces. Each is a separate login with its own password, role and chats.
| Login | Signs in with |
|---|---|
| Their own account | Personal tab: email + password |
| Member of your team | Team member tab: your Account ID + email + password |
| Member of another team | Team member tab: that team's Account ID + email + password |
A member login cannot be used on the Personal tab, and vice versa. A browser holds one login at a time — use a second browser profile to be in two at once.
Removing someone
Settings → Team → ⋮ → Remove from team. The dialog lists every server they
worked on, with a reminder to check for what they may have left behind on
those machines: entries in ~/.ssh/authorized_keys, Linux users created for
them, and scheduled jobs. Removing their DevOps Agent login does not touch any
of that.
Their entries in the activity log are kept — that is the point of an audit log.
Disable rather than remove if they may come back: it blocks sign-in and keeps everything else.
