Skip to content

Team Management

WebDecoy uses role-based access control to manage what team members can do within your organization. Each member has one of three roles.

Role Description Permissions
Owner Organization creator with full control All permissions, including managing other Owners
Admin Can manage most settings and team Cannot change Owner roles or remove Owners
Member View-only access Can view detections and data, cannot make changes
Action Owner Admin Member
View detections and analytics
View team members
Invite new members
Change member roles ✓*
Remove members ✓*
Revoke invitations
Manage domains and decoys
Configure integrations
Manage billing
Delete organization

*Admins cannot modify Owners


To manage your team:

  1. Click your profile avatar (bottom-left)
  2. Select Team

You’ll see the Team Settings page with two main sections:

  • Team Members: Current organization members
  • Pending Invitations: Outstanding invites awaiting acceptance

Owners and Admins can invite new members to the organization.

  1. Click your profile avatar (bottom-left), then Team
  2. Click the Invite Member button
  3. Enter the invitee’s email address
  4. Select a role for the new member:
    • Admin: Full management access (except billing)
    • Member: View-only access
  5. Click Send Invitation

After sending an invitation:

  1. Email is sent to the invitee with a unique invitation link
  2. Invitation appears in your Pending Invitations table
  3. Expiration timer starts (invitations expire after 7 days)
  4. Invitee clicks the link and is taken to the acceptance page

Each pending invitation shows:

Field Description
Email The invited person’s email address
Role The role they’ll receive upon acceptance
Invited By Who sent the invitation
Expires When the invitation will expire
Actions Option to revoke the invitation

To cancel a pending invitation:

  1. Find the invitation in the Pending Invitations table
  2. Click the revoke button (trash icon)
  3. Confirm the revocation

The invitation link will no longer work after revocation.


When someone receives an invitation, they’ll get an email with a unique link.

Email Link → Invitation Page → Sign In (if needed) → Accept → Dashboard

If the invitee doesn’t have a WebDecoy account:

  1. Click the invitation link in the email
  2. View the invitation details (organization name, role, inviter)
  3. Click Sign In to Accept
  4. Create a new account or sign in with Google/GitHub
  5. After authentication, automatically join the organization

If the invitee already has a WebDecoy account:

  1. Click the invitation link in the email
  2. If not logged in, sign in first
  3. View the invitation details
  4. Click Accept Invitation to join
  5. Redirect to the organization dashboard

The invitation page displays:

  • Organization name
  • Who invited them
  • The role they’ll receive
  • Invitation expiration date
  • Accept and Decline buttons

The Team Members table shows all current organization members:

Column Description
Name Member’s display name
Email Member’s email address
Role Current role (Owner, Admin, or Member)
Joined Date they joined the organization
Actions Available management actions

To change someone’s role (Owners and Admins only):

  1. Find the member in the Team Members table
  2. Click the role dropdown next to their name
  3. Select the new role:
    • Owner: Full control (use carefully)
    • Admin: Management access
    • Member: View-only
  4. The change takes effect immediately

Important restrictions:

  • You cannot change your own role (except Owners)
  • Admins cannot promote anyone to Owner
  • Admins cannot demote Owners

To remove someone from the organization:

  1. Find the member in the Team Members table
  2. Click the remove button (X icon)
  3. Confirm the removal

Important restrictions:

  • You cannot remove yourself
  • Admins cannot remove Owners
  • Removed members lose all access immediately

Scenario Recommended Role
Company executives or security leads Owner
IT administrators or DevOps engineers Admin
Developers who need to view detections Member
External auditors or contractors Member
SOC analysts monitoring threats Member
  1. Limit Owner count: Only essential personnel should be Owners
  2. Use Admin sparingly: Give Admin access only when management is needed
  3. Default to Member: Start with Member role and upgrade as needed
  4. Review regularly: Periodically audit team membership
  5. Revoke promptly: Remove access when team members leave the company
  • Verify email addresses before sending invitations
  • Set appropriate roles upfront rather than changing later
  • Follow up if invitations aren’t accepted within a few days
  • Revoke expired invitations to keep the pending list clean

Issue Solution
Invitation email not received Check spam folder; verify email address is correct
Invitation link expired Revoke old invitation and send a new one
Cannot change someone’s role You may not have permission (check if they’re an Owner)
Cannot remove a member You cannot remove Owners as an Admin
Member can’t see detections Verify they’re viewing the correct property

If you encounter issues with team management:

  1. Check the Troubleshooting guide
  2. Contact support at [email protected]

Now that your team is set up: