Skip to main content
Docs menu Account & API

Teams, organizations and roles

How organizations, projects and the five member roles work, the client role for agencies, two-factor sign-in, and the organization audit log.

Last updated 6 min read

On this page

Everything in CompleteStatus belongs to an organization — your billing and team boundary. Inside it, projects group related monitors, alert channels and status pages (one project per site, or per client, works well).

Organizations and projects

An organization is created automatically with your account; you name it in the first step of the onboarding wizard at /onboarding. Your plan, its limits (monitor count, check interval, retention) and its feature flags all live at the organization level — see Getting started for the plan table.

Projects are the unit of day-to-day grouping:

  • Monitors, alert channels and maintenance windows belong to a project.
  • Status pages publish a project's monitors.
  • Client-role members (below) are granted access per project.

Roles and what they can do

Each member of an organization has exactly one role:

Role Manage org, members, API keys, audit log Create/edit monitors & projects View
Owner Yes Yes Everything
Admin Yes Yes Everything
Member No Yes Everything
Viewer No No Everything
Client No No Only their assigned projects

In practice:

  • Owner / Admin are the management roles: only they can open /settings/api-keys and /settings/audit-log, delete projects, and administer the organization.
  • Member is the working role: create and edit monitors, alert rules and channels, but no organization administration.
  • Viewer sees everything in the organization, read-only.
  • Client is view-only and restricted: a client membership carries a list of allowed projects, and the client can only see those.

Invite people from Settings → Team: enter an email address to send an invitation (or copy the invite link and send it yourself), change a member's role, revoke a pending invitation, or remove a member. Invitations are single-use and expire after 14 days. The owner role is not assignable from the roster — ownership transfer is deliberately a separate, confirmed flow.

Seats are limited by plan (Free 1, Pro 1, Business 5, Agency 10), and a pending invitation holds a seat until it is accepted or revoked. The permissions above are enforced everywhere regardless of how a membership was created.

When your plan has fewer seats

Moving to a smaller plan never deletes anyone. Instead, CompleteStatus suspends the members the new plan doesn't cover:

  • the most recently added members beyond the plan's seats (an owner is never suspended), and
  • every Client-role member, if the new plan doesn't include the client role.

A suspended member keeps their account, role and project access, but can't open the organization: they see a page that explains why, and API keys they created stop working. Suspended members don't use a seat, and the Team page marks them Suspended. The organization's owners get one email listing who was suspended.

Suspended members get their access back automatically as soon as the plan has a seat for them again: straight after an upgrade, or at the next daily plan check once a seat frees up. A pending invitation keeps its seat first. Removing a suspended member removes them for good.

The client role for agencies

The client role exists so an agency or MSP can give each customer a login that sees only their own project — their monitors, uptime and incidents — and nothing about the agency's other customers.

The pattern:

  1. Create one project per customer ("Acme Corp", "Beta Ltd", …).
  2. Give each customer's user the client role, scoped to their project.
  3. Optionally publish a status page per project for a fully public view — Agency plans support up to 100 status pages and white-label branding.

A client user cannot create or edit anything, cannot see other projects, and cannot reach organization settings, API keys or the audit log.

Note: The client role is a plan feature: it's included on the Business and Agency plans. On a plan without it, client members are suspended (not removed) until the plan includes it again. Projects themselves are on every plan (Free 1, Pro 3, Business 10, Agency 100). White-label status pages and PDF reports start on Business; Agency adds resale rights and raises bulk audits from 50 to 500 domains per scan — see Security-posture scans for the audit tooling.

Two-factor authentication

CompleteStatus supports TOTP two-factor authentication (standard authenticator apps such as Google Authenticator, 1Password or Authy).

When an account has 2FA enabled, signing in adds a second step:

  1. Enter your email and password as usual.
  2. On the two-factor screen, type the 6-digit code from your authenticator app.
  3. Lost the device? Click through to the recovery option and enter one of your emergency recovery codes instead.

Two-factor codes are rate-limited (5 attempts per minute) to blunt brute-forcing, and enabling 2FA requires confirming a code from the app, so you can't lock yourself out with a mistyped secret.

Warning: Store your recovery codes somewhere safe when you enable 2FA. Each is single-use, and they are the only way in if your authenticator device is lost.

The organization audit log

Owners and admins can review everything that changed in the organization at /settings/audit-log:

  • Who — the acting user (or system) on every entry.
  • What — the action performed; the action dropdown lists every action type recorded in your organization.
  • When — filter by date range (from / to).

Filter by action, actor and date; results are paginated 25 per page. Each row can be expanded to reveal the entry's recorded properties — sensitive values are redacted before they're stored, so secrets never appear in the log.

Use it to answer questions like "who deleted that monitor?", "when was this alert channel changed?", or "which API key was created last week and by whom?".

Security housekeeping for admins

  1. Keep the Owner/Admin set small — those roles control API keys and billing.
  2. Give day-to-day users Member; give stakeholders Viewer; give customers Client.
  3. Review /settings/api-keys periodically: check each key's last-used time and revoke anything stale. Prefer keys with an expiry (set in days at creation).
  4. Skim the audit log after incidents or personnel changes.

Ready to try it?

10 monitors, security grading and email-authentication checks on the free tier — commercial use allowed.