Skip to content

Who can do what, and how they sign in.

Four roles, invitations by email, two-factor sign-in you can require for everyone, and an activity log of what changed. Team seats are unlimited on every plan.

What each role can do
PermissionOwnerAdminMemberViewer
See every client, backup and alertYesYesYesYes
Acknowledge, snooze and resolveYesYesYesNo
Change clients, backups and devicesYesYesYesNo
Channels, API keys and settingsYesYesNoNo
Invite and remove peopleYesYesNoNo
Reveal device loginsYesYesNoNo
Billing, export, activity logYesYesNoNo
Change rolesYesNoNoNo
Delete the workspaceYesNoNoNo

Four roles, from owner to read-only.

Owner
One per workspace. Everything an admin can do, plus changing roles and deleting the workspace.
Admin
Settings, alert channels, API keys, members, billing, the data export and the activity log. Admins can remove members and viewers.
Member
Works the problems and keeps the records: acknowledges, snoozes and resolves, and changes clients, backups and devices.
Viewer
Reads everything and changes nothing. Suits a manager, or the account on the office screen.

Invitations

  1. An owner or admin opens Settings → Members and clicks Invite member.
  2. They enter an email address and pick Admin, Member or Viewer, then Send invitation.
  3. The invitation email carries a link that works for 14 days. Revoke invitation stops it earlier.

If the person already has a BackupSentinel login, no email is sent: you get a link to share, and they accept it by signing in with the invited address. Each account belongs to one workspace.

Sign-in, with two-factor you can require.

Everyone signs in with their own account. Two-factor is set up per person and can be made compulsory for the whole workspace.

Sign-in
Email and password, Microsoft or Google. Sign-in, sign-up and password reset are protected by Cloudflare Turnstile.
Two-factor
Codes from an authenticator app. Each person sets it up under Settings → Security, and is then asked for a code when they sign in.
Require it
An owner or admin who has set up two-factor can turn on Enforce 2FA. Anyone without it is then asked to set it up before they can go on using the dashboard.

Every change is written down.

The activity log in Settings shows what your team and BackupSentinel did in the workspace, newest first. Entries cannot be edited or deleted. Owners and admins can read it, and switch between Team actions, System and All.

Email addresses and IP addresses are not shown in it. Revealing a device login is one of the entries.

Support access

BackupSentinel support can open your workspace to help with a problem you report. Everything done that way is labelled in your activity log.

Those entries name BackupSentinel support as the person who acted, so they never pass for one of your team.

Where the data lives, and how it leaves.

Hosting
The app runs on Vercel in Frankfurt. The database, sign-in, file storage and functions run on Supabase in Frankfurt. Report emails arrive through Amazon SES in Frankfurt, and the raw messages are kept for 30 days.
Export
Settings → Data export → Export all data downloads a JSON file: clients, backup jobs (without passwords), alerts, email metadata and client contacts. Owners and admins can export, including while the workspace is suspended or cancelled.
Deletion
Only the owner can delete the workspace, after typing its name. Any Stripe subscription is cancelled at once, other members lose access, and nothing can be recovered afterwards.

What it does not do.

  • There is no SAML or other single sign-on. Microsoft and Google are sign-in methods for each person's own account.
  • There is no session-timeout setting.
  • Two-factor uses authenticator app codes. There are no SMS codes.
  • The owner role cannot be handed to someone else in the app, and an account belongs to one workspace.

Bring the team in on the first day.

Seats are unlimited on every plan. Start the trial, invite your technicians, and require two-factor before the first alert goes out.