Skip to content

Identity & Access

Who can open a project or an agency, and what they may change there, is decided in one place: Team & Access. Projects and agencies work the same way, with a few differences that are called out below.

  • Membership gives access. Every member can open the project or agency and see almost everything in it.
  • Roles add permissions. A role lets a member change things — operate the modules, manage billing, read the audit log, and so on.
  • Rules automate it. Invitation rules, single sign-on provisioning and expiring memberships keep the team up to date without manual work.

Your own login — password, second factors, email addresses — belongs to your personal account and is described in User Profile.

Open Team & Access in a project or an agency. The member list shows for every member:

ColumnMeaning
UserName and email address. In projects, the bill recipient is marked.
AccessHow the person got access: Direct (invited or added), Single sign-on (added by a provisioning rule) or Via agency (an agency manages the project).
RolesThe roles of the member. A member without any role is shown as Viewer. Roles from your identity provider carry an SSO badge.
MembershipWhen the member joined, and until when the access lasts if it expires.

In an agency, the list additionally shows the client project roles and the project scope of every member — see Agency access to client projects.

Every project and every agency has a number of seats, shown next to the member list (for example 4 / 5 seats).

  • In a project, the module with the most seats sets the base value; add-ons can add seats on top. In an agency, a number of seats is included and add-ons can add more.
  • Every member takes a seat, including members whose access has expired, until you remove them.
  • Agency members do not take seats in the client projects they manage.
  • Seats are checked when someone joins. The dashboard also counts open invitations, so you cannot invite more people than you have free seats.
  • If someone accepts an invitation while no seat is free, the Accept button is locked until a seat becomes free.
  1. Open Team & Access and choose Create Invitation.
  2. Enter the email address and choose the roles. In an agency, also choose the client project roles and the project scope.
  3. Optional: set an expiry for the membership.
  4. The person receives an email. They accept or decline the invitation on their dashboard Home page.
  • An invitation is valid for 7 days. Inviting the same person again replaces the open invitation.
  • People without a TrustComponent account can be invited as well. They receive an email asking them to create an account; the invitation appears on their Home page once they have signed up with exactly the invited email address. A project or agency can have up to 25 such open invitations at the same time.
  • An invitation to an address that belongs to an existing account reaches that account, no matter which of its addresses you used.
  • Before accepting, the invitee sees who invited them, the roles, the client project roles and scope (agencies) and whether the access expires.
  • Open invitations are listed under Team & Access › Invitations, together with who created them: a person, an invitation rule or a single sign-on.
Who can invite
ProjectAdmins
AgencyMaintainers and owners. Only owners can invite someone as owner.

A member without any role can view the project or agency: the modules, their configuration and results, the member list, the settings and the list of invoices. They cannot change anything, and they cannot open the few areas that need a specific role — invoice documents and payment settings, the audit log, contracts and the administration of the team.

Roles add permissions. A member can hold several roles at once; the permissions add up.

RoleWhat it adds
MemberbasicOperate the modules: create and change environments, rules, monitors, alert channels, status pages, checks and schedules; create API keys and webhooks.
Product ManageradvancedEverything a Member can, plus manage modules, plans and add-ons: add a module, activate a paid plan, upgrade, book and cancel add-ons, restore cancelled modules, buy SMS and voice credits.
BillingadvancedBilling profile, bill recipient and payment method, invoice documents (PDF and e-invoice), SMS and voice credits.
AuditoradvancedThe audit log of the project, its export and streaming.
LegaladvancedContracts and the DPA of the project.
AdminbasicFull access. Everything above, plus Team & Access (members, invitations, rules, two-factor enforcement), single sign-on, the agency connection, the project name and deleting modules or the whole project.
  • A project always keeps at least one Admin.
  • The bill recipient must be an Admin. As long as someone is the bill recipient, they keep the Admin role, cannot be removed and cannot leave — change the bill recipient first.
RoleWhat it adds
MemberbasicWork on the client projects in their scope with their client project roles; assign and dismiss items in the work queue.
MaintainerbasicEverything a Member can, plus manage the agency: profile, client details, groups, connecting projects, Team & Access (members, client project roles, scopes, invitations, rules), digest settings and single sign-on.
BillingbasicAgency add-ons and billing, the payout profile of the partner program, and the Billing role in every client project in their scope.
AuditoradvancedThe audit log of the agency, its export, streaming and the agency API keys for the audit log API.
LegaladvancedContracts of the agency.
OwnerbasicFull access, including two-factor enforcement, deleting the agency and granting the Owner role. Owners also hold the Billing role in every client project in their scope.
  • An agency always keeps at least one Owner. Only owners can grant the Owner role or change and remove an owner.
  • A person can own one agency.

Basic roles are available everywhere. Advanced roles — Product Manager, Billing, Auditor and Legal in projects, Auditor and Legal in agencies — and holding several roles at once depend on your plan and add-ons; the dashboard marks them as not included otherwise.

If a project or agency loses access to advanced or multiple roles (for example after cancelling an add-on), members keep the roles they already have. You can only reduce them until the feature is available again.

Client project roles of agency members are the exception: an agency can always assign every project role, and how they apply depends on each client project — see Agency access to client projects.

An agency manages its client projects through its own team. Members of the agency do not need to be invited into every client project; instead, two settings per agency member decide what they can do there:

  • Project scope — which client projects the member can open: all client projects (including projects connected later) or selected groups and projects. Projects added to a group later are included automatically.
  • Client project roles — the project roles the member holds in every client project inside their scope. The agency can assign every project role, and several at once, whatever its own add-ons.
SituationAccess in the client project
Project in scope, client project roles setThe member works with these roles.
Project in scope that does not include advanced rolesProduct Manager, Billing, Auditor and Legal count as Member there. Admin and Member apply unchanged.
Project in scope, no client project roleThe member can view the project, but change nothing.
Project outside the scopeNo access.
Agency Owner or Billing member, project in scopeAdditionally the Billing role — in a project without advanced roles it counts as Member, like every advanced role.
  • Whether a client project includes advanced roles depends on that project’s plan and add-ons (Governance Enterprise), not on the agency’s. When a project gains or loses them, the access of the agency team changes at once. Without them, only Admins of the project can handle its billing.
  • Agency members appear in the project’s member list as Via agency. Their roles are managed in the agency, not in the project.
  • If a person is a direct member of the project and reaches it through the agency, the roles of both add up.
  • When an agency stops managing a project, the access through the agency ends immediately. See Ending the management.
  • Owners and maintainers see every client project in the agency’s lists. What anyone can open and change inside a client project follows their own scope and client project roles.

A membership can end automatically on a set day — for freelancers, auditors or temporary support.

  • Set it when inviting, or later with Edit roles & access: Never, In … days or Until a date.
  • From that day on, the member keeps the seat but loses access. The member list shows Access ended …; Restore access gives it back, Remove member frees the seat.
  • Admins and the bill recipient (projects) and owners (agencies) cannot have an expiry.

An invitation rule invites new people automatically when they sign up with an email address of one of your domains — useful when everyone at your company should find the project ready on their Home page.

Open Team & Access › Invitation Rules and create a rule:

SettingNotes
NameFor your own overview.
Email domainsUp to 20 domains, one per line, for example example.com.
RolesThe roles the invitation grants. In agencies, also the client project roles.
Access ends afterOptional: the membership ends this many days after the invitation.
ActiveA paused rule keeps its settings but invites nobody.
  • Only new sign-ups are invited. The person still accepts the invitation themselves.
  • The domain is not verified. Anyone who can create an address at that domain will be invited — use rules only for domains whose mailboxes you control. To give people access based on your identity provider instead, use single sign-on provisioning.
  • If your plan no longer includes invitation rules, existing rules are suspended: they invite nobody until the feature is available again. You can still pause or delete them.
  • Deleting a rule does not withdraw the invitations it already sent.
  • In agencies, only owners can change rules that grant the Owner role.

You can require every member to confirm their sign-in with a second factor before they can open anything in the project or agency.

Open Team & Access › Two-Factor Authentication and choose the requirement:

RequirementAccepted second factors
Not required—
Required, verified by TrustComponentAn authenticator app or a passkey / security key set up in the member’s TrustComponent account.
Required, verified by TrustComponent or your single sign-on providerThe above, or a second factor confirmed by your identity provider during single sign-on.
  • Members whose current sign-in does not meet the requirement are sent to a page where they set up a second factor or confirm their sign-in again. They do not lose their membership.
  • You can only switch on a requirement that your own sign-in already meets — so you never lock yourself out.
  • A client project reached through an agency applies the stricter requirement of the project and the agency.
  • Changing the requirement is reserved to admins (projects) and owners (agencies).
  • If your plan no longer includes two-factor enforcement, the current requirement stays in force; you can only loosen or switch it off.
  • Members of our support team are exempt, so we can still help you.

Every direct member can leave on their own — from the context menu of the project or agency overview.

  • The bill recipient of a project cannot leave until someone else is the bill recipient.
  • The last owner of an agency cannot leave. Make someone else owner first, or delete the agency.
  • Access that comes through an agency cannot be left from the project; it ends with the agency membership or with the agency’s project scope.
  • To delete your whole account, see Deleting your account — it leaves everything you can leave automatically.

The invitation email did not arrive. Check the spam folder and the address. The invitation also appears on the invitee’s dashboard Home page once they are signed in with an account that owns the address. If they have no account yet, they must sign up with exactly the invited address.

The invitation has expired. Invitations are valid for 7 days. Create a new one — it replaces the old invitation.

The Accept button is locked. All seats are taken. An admin or owner can remove a member, or add seats through the plan or add-ons. The invitation stays open and can be accepted once a seat is free.

I cannot remove a member or take away their Admin role. The member is the bill recipient. Change the bill recipient first. A project must also always keep at least one Admin, an agency at least one Owner.

A role cannot be removed and shows an SSO badge. The role comes from a provisioning rule. It would come back at the next sign-in. Change the rule or the groups at your identity provider instead.

An agency member cannot open a client project. The project is outside the member’s project scope. A maintainer can widen the scope or add the project to one of the member’s groups.

An agency member can open a client project but not change anything. The member has no client project role. A maintainer can add one under Team & Access › Edit roles & access.

The dashboard asks for a second factor although I am signed in. The project or agency requires two-factor authentication. Set up an authenticator app or a passkey in your user profile, or sign in again and confirm the second factor.