Documentation menu
Team and security
Roles, invitations, two-factor sign-in and the activity log.
Last updated
Everyone on your team signs in to the same workspace with a role that sets what they can change. This page covers the roles, invitations, sign-in and two-factor authentication, the activity log, and what BackupSentinel does to protect your account. For how and where data is stored, see Security.
Roles
A workspace has one Owner. Everyone else is an Admin, a Member or a Viewer. Team seats are unlimited on every plan.
| What you can do | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| See every client, backup, report and the Backup Matrix; use TV mode; build a client report and download CSVs | Yes | Yes | Yes | Yes |
| Add and edit clients, backup jobs, devices and parsing rules; work the Inbox | Yes | Yes | Yes | No |
| Acknowledge, snooze, resolve and assign items in Needs attention | Yes | Yes | Yes | No |
| Save reports, schedule reports, create and revoke share links | Yes | Yes | Yes | No |
| Manage workspace settings, alert channels and API keys | Yes | Yes | No | No |
| Reveal stored device passwords | Yes | Yes | No | No |
| Invite people and remove members and viewers | Yes | Yes | No | No |
| Manage billing, export all data, read the activity log | Yes | Yes | No | No |
| Change a member's role and remove admins | Yes | No | No | No |
| Delete the workspace | Yes | No | No | No |
A viewer can move through Needs attention and open items, but cannot act on them.
Invitations
Owners and admins invite people from Settings → Members with Invite member: enter an email address and choose Admin, Member or Viewer. The invitation is emailed and expires after 14 days. Until it is accepted it is listed under Members, where you can revoke it.
An account belongs to one workspace. If the address already belongs to another BackupSentinel workspace, the invitation is refused.
Changing roles and removing members
- Changing a role: only the owner can change someone's role, between Admin, Member and Viewer. Nobody can change their own role, and the Owner role cannot be given to someone else from Settings.
- Removing someone: the owner can remove anyone except themselves. An admin can remove members and viewers, but not other admins.
Every invitation, role change and removal is recorded in the activity log.
Signing in
You can sign in with an email address and password, with Microsoft, or with Google. Sign-in, sign-up and password reset are protected by Cloudflare Turnstile, a check against automated attempts.
Change your password and name in Settings → My account. To change the email address you sign in with, contact support.
Two-factor authentication
Two-factor authentication adds a code from an authenticator app (TOTP) to every sign-in. Set it up in Settings → Security: scan the QR code with your app (or type the key by hand) and confirm with the six-digit code it shows.
To require it for everyone, an owner or admin ticks Required under Enforce 2FA in Settings → Security. You must set up two-factor authentication on your own account first. Once it is required, anyone who has not set it up is sent to Settings → Security to do so before they can use the dashboard.
The activity log
Settings → Activity log lists what your team and BackupSentinel did in the workspace, newest first: invitations, role changes and removals, alert channel and API key changes, share links created and revoked, device passwords revealed, data exports and more. Switch between Team actions, System and All.
- Only owners and admins can read it.
- Entries cannot be edited or deleted.
- Personal data such as email addresses and IP addresses is hidden in the log.
- Anything done by BackupSentinel support is labelled "BackupSentinel support", or "(via BackupSentinel support)" next to the action.
Support access
BackupSentinel support can open your workspace to help with a problem you report. Everything done that way is labelled in your activity log.
Data export
Owners and admins can download a JSON file of the whole workspace from Settings → Data export with Export: clients, backup jobs (without stored passwords), alerts, the metadata of report emails, and client contacts. The export is recorded in the activity log, and it works even when the workspace is suspended or cancelled.
Deleting the workspace
The owner can delete the workspace from Settings → Data export, under Delete workspace, by typing the workspace name to confirm. Any active subscription is cancelled first, then all clients, jobs, alerts, reports and logins are deleted, and every member loses access at once. This cannot be undone, so export your data first if you need it.
How your account is protected
- The app is served over HTTPS only, with HSTS (two years, preloaded), a Content Security Policy, and
X-Frame-Options: DENYso it cannot be framed by another site. - API keys and share-link tokens are stored as hashes. A key or link is shown once, when it is created.
- Device passwords are encrypted with AES-256-GCM, and only owners and admins can reveal them.
More on hosting and data handling is on the Security page.
Limits
- There is no single sign-on (SSO or SAML). Sign in with email and password, Microsoft or Google.
- There is no setting for session timeout.
- An account belongs to one workspace.
- The Owner role cannot be transferred from Settings.