Updated 2026-09-29
An account can have more than one person on it. Each person has a role, and the role decides what they can see and change. You manage all of this on the Team page in the dashboard.
Roles
Every account has two built-in roles, plus any custom roles you create.
| Role | What it can do |
|---|---|
| Owner | Everything, including transferring ownership. Every account has exactly one Owner: the person who signed up, unless ownership has been handed over since. The Owner can't be disabled, removed or demoted. |
| Admin | Everything the Owner can do except transfer ownership or change the Owner. Admins create and edit roles, invite people as Admin, manage support access and rotate the webhook signing secret. |
| Custom roles | Exactly the permissions ticked for that role, and nothing else. |
The built-in roles can't be edited, renamed or deleted.
The Member and Viewer roles
Every account starts with two custom roles, so you have sensible defaults straight away:
- Member: day-to-day monitoring. View checks and pause, resume or test-run them. View reports. View incidents and respond to them: acknowledge, add notes and post updates. View alert channels, test and verify them, and see their delivery logs. View status pages and their subscribers. View maintenance windows.
- Viewer: read-only. View checks, results and uptime, and view maintenance windows.
They work like any other custom role: an Owner or Admin can rename, change or delete them.
Custom roles and permissions
An Owner or Admin creates a role by ticking the permissions it should have. Some permissions include the ones below them. For example, ticking Create, edit and delete checks also ticks, and locks, Pause, resume and test-run checks and View checks, results and uptime.
| Area | Permissions |
|---|---|
| Monitoring | View checks, results and uptime · Pause, resume and test-run checks · Create, edit and delete checks · View uptime reports |
| Incidents | View incidents (and, once our mobile apps are released, receive push alerts in them) · Acknowledge, add notes and post incident updates · Open incidents manually |
| Alerting | View, test and verify alert channels and delivery logs · Create, edit and delete alert channels |
| Status pages | View status pages and their subscribers · Create, edit and delete status pages and subscribers |
| Maintenance | View maintenance windows · Schedule, edit and delete maintenance windows |
| Billing | View plan, usage and invoices · Change plan, add-ons and card; cancel or resume |
| Account | Edit account settings and summary emails · Create and revoke API keys · Manage the team |
A few things to know when you build a role:
- Updating a status page. Editing a page or its subscribers needs Create, edit and delete status pages. Posting an incident update, which is what your visitors read, needs Acknowledge, add notes and post incident updates. A "status page editor" role usually wants both.
- Attaching alert channels to a check needs permission to see alert channels as well as permission to edit checks.
- Everyone on the account can see the account overview, the team list, the activity feed and the roles list, whatever their role.
- Some permissions reach further than they look. Anyone who can change the plan can downgrade it, which may disable members over the new seat limit once the downgrade takes effect at the next renewal. Anyone who can create and revoke API keys can revoke keys other people created.
- An account can have up to 25 roles in total, counting the Member and Viewer presets. Role names must be unique on the account, and every role needs at least one permission.
Changes to a role apply straight away to everyone who has it.
What people can and can't hand out
Whoever has Manage the team can invite, remove, enable and disable members and change their roles, with these limits:
- Nobody can change their own role, disable themselves or remove themselves. To leave an account, use Leave account on the Team page.
- You can only give out what you have. You can invite someone into, or move someone to, a role whose permissions are all ones you hold yourself. A role equal to your own is fine. A role with anything extra isn't.
- You can only manage people at or below your level. If someone's role includes a permission you don't have, you can't change, disable or remove them, or resend or revoke an invite for that role.
- Only an Owner or Admin can make someone an Admin, and only an Owner or Admin can create, edit or delete roles.
- Nobody can be invited or promoted to Owner. Ownership only moves by transfer (see below).
Inviting someone
- On the Team page, choose Invite.
- Enter their email address and pick a role. The dialog shows what that role can do.
- They get an email with a link. The link expires after 7 days.
They join the account only when they open the link and accept, signed in with the address you invited. An invite can't be used from a different email address. If they don't have a login yet, one is created when they accept.
While an invite is waiting you can:
- Resend it. This sends a new link, makes the old one stop working and restarts the 7 days.
- Revoke it, which frees the seat it was holding.
An invite also stops working if the person who sent it is removed, or loses the permissions they needed to send it, before it's accepted. Inviting the same address again replaces the earlier invite.
Seats
Each plan includes a number of user seats:
| Plan | Seats included |
|---|---|
| Starter | 1 |
| Professional | 3 |
| Enterprise | 20 |
Seats are counted as:
- the Owner and every enabled member, plus
- every invite that is still waiting to be accepted.
Disabled members and expired or revoked invites don't use a seat. On Starter, the one seat is the Owner's, so you need an extra seat before you can invite anyone.
When you run out, inviting someone, re-enabling a member or accepting an invite is refused until a seat is free. You can free one by revoking a waiting invite or disabling or removing a member, or buy extra seats as an add-on on the Billing page. Seat add-ons are available on every plan.
If a downgrade or a smaller seat add-on leaves you over the limit when it takes effect at your next renewal, waiting invites are revoked first, newest first. If you're still over, the most recently added members are disabled. The Owner is never disabled.
Changing, disabling or removing someone
- Change role: pick a new role from the member's row. It takes effect on their next action.
- Disable: they lose access straight away but keep their role, so you can re-enable them later if there's a seat for them.
- Remove: they lose access straight away and have to be invited again to come back. (Once the mobile apps are released, their push notifications for the account stop too.)
API keys belong to the account, not to the person who created them. They keep working after that person leaves. When you remove or disable someone, or change them to a role that no longer covers the scopes of keys they created, the dashboard lists those keys and offers to revoke them. That option is ticked by default.
Transferring ownership
Only the Owner can transfer ownership. On the Team page, choose Transfer ownership on your own row, then:
- pick the new Owner. They must be an enabled member who has signed in at least once;
- choose whether to stay on the account as an Admin or leave it;
- type the account name to confirm.
Both of you get an email. If the account's billing email was the old Owner's, billing email moves to the new Owner too.
Admins can't transfer ownership. Neither can our support team, even when you've given them support access.
If the Owner can't be reached, for example because they've left the company, contact support. After we've verified who you are and that you're entitled to take over the account, we can move ownership to an existing member. We record why we did it on the account's activity feed, and we email both the previous and the new Owner.