docs / Administration

Team, roles & MFA

Invite your team and control what each member can do, with two-factor authentication for sensitive accounts.

Roles (RBAC)

  • Owner — manages everything, including billing and the team
  • Admin — issues/revokes certs, sets policy
  • Member — views and works within granted permissions

Account security

  • Mandatory MFA for every owner/admin
  • 4-eyes approval — critical actions (revoke, delete tenant, set policy) require a second approver
  • SSO (OIDC) per tenant for enterprises