Team and sign-in
Who can do what in an organization, and how to keep accounts safe.
Roles
Everyone in an organization has one role there. The same person can be an owner in one organization and a viewer in another.
| Role | Can |
|---|---|
| Viewer | Open flows, run the phone and scenarios, and see who else is here |
| Editor | Everything a viewer can, plus change flows and scenarios, publish versions and deploy to staging |
| Admin | Everything an editor can, plus put versions live, hold each environment's variables and secrets, invite and manage members, and change the organization |
| Owner | Everything an admin can, plus make and remove other owners |
Invite people under Settings → People. Settings is in the account menu: your own tabs come first (Signing in, Devices, API tokens), then the organization's (People, Organization, Security).
Signing in safely
- A passkey signs you in with your fingerprint, face or device PIN. It cannot be phished, and an account can use passkeys with no password at all.
- A second step adds a code from an authenticator app to a password.
- Recovery codes get you back in if you lose your device. Only you see them, once, so keep them somewhere safe. Making new ones replaces the old.
- Settings → Devices lists the devices you are signed in on, and lets you sign any of them out.
Asking more of your members
An owner can set what the organization asks of a sign-in, under Settings → Security:
| Setting | What it means |
|---|---|
| Any way of signing in | A password alone is enough. |
| A second step | A password also needs a code from an authenticator app. A passkey or single sign-on passes as it is. |
| A passkey | A password no longer signs anyone in, with or without a code. A passkey or single sign-on does. |
| Single sign-on only | Only your identity provider signs members in. |
Single sign-on uses your own OpenID Connect provider. Set it up on the same tab before requiring it.