Skip to content

Learn · Guides

Invite your team and set roles

Add people, give each one the access their job needs, and see the record of it.

Checked against the product on · written for people who run the account

Five roles exist. Each one grants a fixed set of screens and actions, and every grant is written to the audit log.

The roles and what each one can do.
RoleCan seeCan change
OwnerEverything in the organization.Everything, including billing and deletion.
AdminEverything in their work areas.Rules, feeds, packs, keys, people.
ReviewerWatch, reviews, and records in their work areas.Review outcomes.
ReaderWatch, reviews, and records in their work areas.Nothing.
DeveloperDeveloper tools and the docs.Their own sandbox keys.
console.dmzagent.com/team

Prove

Team & billing

1PeopleRolesPlan
2
PersonRoleWork areasAdded
dana@example.comAdminAll2026-06-02
sam@example.comReviewerplant-east2026-06-14
lee@example.comReaderplant-east2026-07-03
3Manage planInvite someone
Figure. The team screen. Role and work areas are set per person. The team screen: members with their role and work areas, and the plan summary.
  1. Open Team & billing.1

  2. Read the current roster and the work areas each person holds.2

  3. Select Invite someone, enter an email, and pick a role and work areas.3

    The invitation expires after seven days.

Read the record afterwards

console.dmzagent.com/settings/audit

Prove

Audit log

1All actorsLast 30 daysExport CSV
2
TimeWhoActionTarget
12:31dana@Role changed to adminsam@
11:02dana@API key createdck_test_…9b17
09:44sam@Rule pack pinnedSupport conduct 1.1.2
3Append-only. Secret material is stripped before an entry is written.
Figure. The audit log. Role changes, key lifecycle, and settings edits, with the actor on every row. The workspace audit log: who changed what, when, and against which target.
  1. Open Settings, then Audit log.1

  2. Find the row for the role you granted.2

    The actor email stays on the row after a person leaves the account.

  3. Read the append-only line.3