Skip to content

Users and permissions

Each organization has its own user list. Check the selected organization before inviting someone or changing their permissions.

This matrix describes actions offered in the application for a role assigned directly in the organization. Service access also depends on subscription status.

ActionOwnerMemberReaderBilling
View and search logsYesYesYesNo
Download logs and prepare personal period exportsYesYesYesNo
View and export audit logsYesYesYesNo
Create, update or delete a locationYesYesNoNo
Add or remove allowed IP addressesYesYesNoNo
View the user listYesYesYesNo
Invite, remove a user or change their roleYesNoNoNo
Update or delete the organizationYesNoNoNo
View the planYesYesYesYes
Manage the subscription and payment methodsYesNoNoYes

Reader does not mean “no downloads”. This role can retrieve copies of logs. Requests displayed in My exports belong to the account that created them.

Additional permissions may come from MSP access to a linked organization. If access remains after an organization role is removed, also check that membership with your administrator.

  1. Open Users in the relevant organization.
  2. Select the invitation action.
  3. Enter the email address and choose a role.
  4. Send the invitation; the person must accept it to join the organization.

Invitations explains how to accept, reject and track invitations. If the user limit blocks an invitation, see Plans and usage.

In Users, select the role change or removal action for the relevant person. These actions require the Owner role.

Then check the user list and audit logs. Already downloaded files cannot be recalled, and previously issued links may remain usable until they expire.

  • An action is missing or denied: check your role, selected organization and subscription status.
  • An invitation remains pending: verify the invited address and ask the person to open Invitations using that same account.
  • Someone must no longer access logs: remove direct access and have any MSP access checked as well.

Allowed IP addresses control log sources; they do not grant permissions to application users.