Team & permissions
Invite people into your DomainCare organization, choose what each of them can do, and switch between organizations you belong to.
Team & permissions
A DomainCare organization can hold as many people as you like. Each person gets a role that decides what they can do.
Adding people never changes your bill. DomainCare charges per domain, not per person — there is no seat limit and no per-user fee on any plan.
Invite someone
Go to Settings → Team, enter their email address, pick a role, and send the invite. They get a link, sign in (or create an account), and land in your organization.
Only owners and admins can invite people.
A pending invite can be resent or cancelled from the same page before it is accepted.
Resending re-sends the same link and extends its expiry — useful if the first email was lost or the invite has already timed out. It does not invalidate the original link. To make a link stop working, cancel the invitation and send a new one.
Roles
| Role | Billing | Manage people | Domains | Incidents & re-checks |
|---|---|---|---|---|
| Owner | Yes | Yes | Full, including delete | Yes |
| Admin | View only | Yes | Full, including delete | Yes |
| Member | No | No | Add, edit, re-check | Yes |
| Viewer | No | No | Read only | No |
A few rules worth knowing:
- Only an owner can create or change another owner. An admin cannot promote someone (including themselves) to owner, because owner carries billing access.
- An organization always keeps at least one owner. The last owner cannot be removed or demoted — promote someone else first.
- You cannot change or remove your own membership. Ask another owner.
- Viewer really is read-only. A viewer cannot acknowledge an incident or trigger a re-check — a re-check runs a real probe and records a result, so it counts as a change, not a read.
- Member cannot delete a domain. Deleting a domain also deletes its check history, and that cannot be undone from the interface.
Choosing a role
- Someone who runs the domains day to day → Member.
- A colleague who should also manage people and settings → Admin.
- A client or stakeholder who should see status but change nothing → Viewer.
- Someone who needs to handle the subscription → Owner.
Belonging to more than one organization
If you are a member of several organizations, an Active organization selector appears at the top of Settings → Team. Switching changes what the whole app shows — domains, alerts, dashboard, and billing all follow the organization you have selected.
If you only belong to one organization, which is the case for most accounts, the selector is not shown.
Choosing which domains someone sees
A newly invited member starts with no domain access. They can sign in, but their domain list is empty until you grant something — deliberately, so that adding a person is never accidentally the same as showing them everything.
To grant access, open Settings → Team, find the member, and either switch their domain access to All domains, or leave it on Only selected and tick the domains they should reach.
Members who already existed before this feature shipped keep access to every domain — nothing changed for them.
A restricted member sees those domains and nothing else across the app's domain surfaces: the domain list, the dashboard counts and health rollups, the recent activity feed, per-domain pages and their event history, the delivery log, and the data export. Opening a URL for a domain they were not granted returns "not found", exactly as a domain that does not exist would.
The two exceptions are named below, and they are the reason to read the next section before inviting someone you don't fully trust.
Owners and admins always see every domain. Their role grants it, so the access control does not appear for them. If you need to restrict someone, give them the Member or Viewer role first.
Changing access takes effect on their next request — there is nothing to wait for and no need for them to sign out.
What is not scoped yet
Two surfaces still work at the organization level, and both are being changed next:
- API keys and the MCP integration. A key reaches every domain in the organization. Only owners and admins can create one, so a restricted member cannot mint a key that exceeds their own access — but a key handed to them will show more than the interface does.
- Alerts. Notification routing is still per-organization, so a restricted member subscribed to a channel may receive alerts for domains they cannot open.