Skip to content

Team Management

WebDecoy uses role-based access control to manage what team members can do within your organization. Each member has one of three roles.

RoleDescriptionPermissions
OwnerOrganization creator with full controlAll permissions, including managing other Owners
AdminCan manage most settings and teamCannot change Owner roles or remove Owners
MemberView-only accessCan view detections and data, cannot make changes
ActionOwnerAdminMember
View detections and analytics
View team members
Invite new members
Change member roles✓*
Remove members✓*
Revoke invitations
Manage domains and decoys
Configure integrations
Manage billing
Delete organization

*Admins cannot modify Owners


To manage your team:

  1. Click Settings in the sidebar
  2. Select Team

You’ll see the Team Settings page with two main sections:

  • Team Members: Current organization members
  • Pending Invitations: Outstanding invites awaiting acceptance

Owners and Admins can invite new members to the organization.

  1. Navigate to Settings → Team
  2. Click the Invite Member button
  3. Enter the invitee’s email address
  4. Select a role for the new member:
    • Admin: Full management access (except billing)
    • Member: View-only access
  5. Click Send Invitation

After sending an invitation:

  1. Email is sent to the invitee with a unique invitation link
  2. Invitation appears in your Pending Invitations table
  3. Expiration timer starts (invitations expire after 7 days)
  4. Invitee clicks the link and is taken to the acceptance page

Each pending invitation shows:

FieldDescription
EmailThe invited person’s email address
RoleThe role they’ll receive upon acceptance
Invited ByWho sent the invitation
ExpiresWhen the invitation will expire
ActionsOption to revoke the invitation

To cancel a pending invitation:

  1. Find the invitation in the Pending Invitations table
  2. Click the revoke button (trash icon)
  3. Confirm the revocation

The invitation link will no longer work after revocation.


When someone receives an invitation, they’ll get an email with a unique link.

Email Link → Invitation Page → Sign In (if needed) → Accept → Dashboard

If the invitee doesn’t have a WebDecoy account:

  1. Click the invitation link in the email
  2. View the invitation details (organization name, role, inviter)
  3. Click Sign In to Accept
  4. Create a new account or sign in with Google/GitHub
  5. After authentication, automatically join the organization

If the invitee already has a WebDecoy account:

  1. Click the invitation link in the email
  2. If not logged in, sign in first
  3. View the invitation details
  4. Click Accept Invitation to join
  5. Redirect to the organization dashboard

The invitation page displays:

  • Organization name
  • Who invited them
  • The role they’ll receive
  • Invitation expiration date
  • Accept and Decline buttons

The Team Members table shows all current organization members:

ColumnDescription
NameMember’s display name
EmailMember’s email address
RoleCurrent role (Owner, Admin, or Member)
JoinedDate they joined the organization
ActionsAvailable management actions

To change someone’s role (Owners and Admins only):

  1. Find the member in the Team Members table
  2. Click the role dropdown next to their name
  3. Select the new role:
    • Owner: Full control (use carefully)
    • Admin: Management access
    • Member: View-only
  4. The change takes effect immediately

Important restrictions:

  • You cannot change your own role (except Owners)
  • Admins cannot promote anyone to Owner
  • Admins cannot demote Owners

To remove someone from the organization:

  1. Find the member in the Team Members table
  2. Click the remove button (X icon)
  3. Confirm the removal

Important restrictions:

  • You cannot remove yourself
  • Admins cannot remove Owners
  • Removed members lose all access immediately

ScenarioRecommended Role
Company executives or security leadsOwner
IT administrators or DevOps engineersAdmin
Developers who need to view detectionsMember
External auditors or contractorsMember
SOC analysts monitoring threatsMember
  1. Limit Owner count: Only essential personnel should be Owners
  2. Use Admin sparingly: Give Admin access only when management is needed
  3. Default to Member: Start with Member role and upgrade as needed
  4. Review regularly: Periodically audit team membership
  5. Revoke promptly: Remove access when team members leave the company
  • Verify email addresses before sending invitations
  • Set appropriate roles upfront rather than changing later
  • Follow up if invitations aren’t accepted within a few days
  • Revoke expired invitations to keep the pending list clean

IssueSolution
Invitation email not receivedCheck spam folder; verify email address is correct
Invitation link expiredRevoke old invitation and send a new one
Cannot change someone’s roleYou may not have permission (check if they’re an Owner)
Cannot remove a memberYou cannot remove Owners as an Admin
Member can’t see detectionsVerify they’re viewing the correct property

If you encounter issues with team management:

  1. Check the Troubleshooting guide
  2. Contact support at [email protected]

Now that your team is set up: