Who can do what, and how they sign in.
Four roles, invitations by email, two-factor sign-in you can require for everyone, and an activity log of what changed. Team seats are unlimited on every plan.
| Permission | Owner | Admin | Member | Viewer |
|---|---|---|---|---|
| See every client, backup and alert | Yes | Yes | Yes | Yes |
| Acknowledge, snooze and resolve | Yes | Yes | Yes | No |
| Change clients, backups and devices | Yes | Yes | Yes | No |
| Channels, API keys and settings | Yes | Yes | No | No |
| Invite and remove people | Yes | Yes | No | No |
| Reveal device logins | Yes | Yes | No | No |
| Billing, export, activity log | Yes | Yes | No | No |
| Change roles | Yes | No | No | No |
| Delete the workspace | Yes | No | No | No |
Four roles, from owner to read-only.
- Owner
- One per workspace. Everything an admin can do, plus changing roles and deleting the workspace.
- Admin
- Settings, alert channels, API keys, members, billing, the data export and the activity log. Admins can remove members and viewers.
- Member
- Works the problems and keeps the records: acknowledges, snoozes and resolves, and changes clients, backups and devices.
- Viewer
- Reads everything and changes nothing. Suits a manager, or the account on the office screen.
Invitations
- An owner or admin opens Settings → Members and clicks Invite member.
- They enter an email address and pick Admin, Member or Viewer, then Send invitation.
- The invitation email carries a link that works for 14 days. Revoke invitation stops it earlier.
If the person already has a BackupSentinel login, no email is sent: you get a link to share, and they accept it by signing in with the invited address. Each account belongs to one workspace.
Sign-in, with two-factor you can require.
Everyone signs in with their own account. Two-factor is set up per person and can be made compulsory for the whole workspace.
- Sign-in
- Email and password, Microsoft or Google. Sign-in, sign-up and password reset are protected by Cloudflare Turnstile.
- Two-factor
- Codes from an authenticator app. Each person sets it up under Settings → Security, and is then asked for a code when they sign in.
- Require it
- An owner or admin who has set up two-factor can turn on Enforce 2FA. Anyone without it is then asked to set it up before they can go on using the dashboard.
Every change is written down.
The activity log in Settings shows what your team and BackupSentinel did in the workspace, newest first. Entries cannot be edited or deleted. Owners and admins can read it, and switch between Team actions, System and All.
Email addresses and IP addresses are not shown in it. Revealing a device login is one of the entries.
Support access
BackupSentinel support can open your workspace to help with a problem you report. Everything done that way is labelled in your activity log.
Those entries name BackupSentinel support as the person who acted, so they never pass for one of your team.
Where the data lives, and how it leaves.
- Hosting
- The app runs on Vercel in Frankfurt. The database, sign-in, file storage and functions run on Supabase in Frankfurt. Report emails arrive through Amazon SES in Frankfurt, and the raw messages are kept for 30 days.
- Export
- Settings → Data export → Export all data downloads a JSON file: clients, backup jobs (without passwords), alerts, email metadata and client contacts. Owners and admins can export, including while the workspace is suspended or cancelled.
- Deletion
- Only the owner can delete the workspace, after typing its name. Any Stripe subscription is cancelled at once, other members lose access, and nothing can be recovered afterwards.
What it does not do.
- There is no SAML or other single sign-on. Microsoft and Google are sign-in methods for each person's own account.
- There is no session-timeout setting.
- Two-factor uses authenticator app codes. There are no SMS codes.
- The owner role cannot be handed to someone else in the app, and an account belongs to one workspace.
Bring the team in on the first day.
Seats are unlimited on every plan. Start the trial, invite your technicians, and require two-factor before the first alert goes out.