Skip to content

Workspace

Teams and roles

Invite teammates to a DNS workspace, assign roles, and control who can edit zones, connect providers, apply changes, manage billing, or view activity.

4 min read

On this page

Teams let people share a workspace while reserving provider writes, cutovers and billing changes for higher roles. The key point is that roles are hierarchical: Member can inspect and preview, Admin can change DNS and team settings, and Owner adds role assignment and subscription control.

Role permissions#

Every server operation checks that the signed-in user belongs to the selected workspace, then compares the membership role with the minimum role for that action. An Owner inherits Admin and Member capabilities; an Admin inherits Member capabilities.

CapabilityMemberAdminOwner
View connections, zones, migrations, notifications, reports and activityYesYesYes
Create a migration, change preview options, rebuild a preview and export its zone fileYesYesYes
Run migration verification or a managed-zone drift checkYesYesYes
Connect, check or remove provider and registrar credentialsNoYesYes
Apply, roll back or delete a migrationNoYesYes
Start, confirm or revert a nameserver cutoverNoYesYes
Create, import, edit, push or remove a managed zone; create or restore a backupNoYesYes
Add, test, pause, resume or delete notification channelsNoYesYes
Invite Admins or Members, revoke invitations and remove non-Owner membersNoYesYes
Buy a one-time migration entitlementNoYesYes
Assign roles or remove another OwnerNoNoYes
Start or manage a Pro or Agency subscriptionNoNoYes
Leave the workspaceYesYesYes

Migration verification and managed-zone drift checks are reads, so Members may start them. The zone service also accepts a Member preview request, but the current zone UI hides Preview changes for Members. Applying, pushing, rolling back, and cutover can change provider or registrar state and require Admin or Owner.

Invite someone#

The Free, Pro and Agency plans include 1, 3 and 15 seats respectively. Active members and unexpired pending invitations both count toward the limit shown on Team.

Open the team page

Go to Team. Admins and Owners see Invite someone, the current seat meter and the invitation form. Members can view the roster and pending invitations but cannot create or revoke them.

Enter the invitation

In Email, enter the address the person will use to sign in. Choose Member for read and preview access or Admin for provider and DNS changes. New invitations cannot assign Owner.

Send it

Select Send invite. DNSMigrator normalizes the address, rejects an existing member, checks the seat limit, creates a single-use token and sends an email. The pending invitation appears under Pending invitations.

Have the recipient accept

The recipient must sign in with the same email address. The link expires after 7 days. Acceptance creates the membership with the role chosen in the invitation and switches the user into that workspace.

If all seats are in use, Team shows Add seats, which opens Billing. Seats are fixed by plan rather than purchased one at a time; compare the exact limits in Plans and billing.

An Admin or Owner can select Revoke beside an unaccepted invitation. Revoked, accepted and expired invitations no longer appear as pending and no longer count toward the displayed seat usage.

Change a role#

Only an Owner sees editable role selectors in the Members list. Choose Owner, Admin or Member beside a person; the change applies to later requests immediately.

To transfer day-to-day ownership:

Promote the replacement

As an Owner, change the other member’s role to Owner. Invitations cannot create an Owner directly, so the person must accept as Admin or Member first.

Confirm there are two Owners

The service prevents the last Owner from being demoted or removed. Keep both memberships until the promotion has completed.

Demote or leave

Change your own role after another Owner exists, or select Leave. The workspace retains at least one Owner.

Owners control subscription checkout and the external billing portal. Promote only someone who should be able to change roles, remove Owners and manage the workspace subscription.

Remove a member or leave#

Admins and Owners see Remove for other members. An Admin can remove Members and Admins, but only an Owner can remove an Owner. DNSMigrator also refuses to remove the workspace’s sole Owner.

Every person sees Leave on their own row. Leaving deletes that membership; it does not delete the workspace, provider connections, zones, migrations or audit history. If you are the only Owner, make someone else an Owner first.

There is no separate confirmation dialog in the current Team view. Check the row before selecting Remove or Leave.

Work across workspaces#

Membership and authorization are scoped by workspace ID. Provider connections, migrations, managed zones, notification channels, billing status and audit entries are queried only for the active workspace. A role in one workspace grants no access to another.

The initial personal workspace is created with the user as Owner. Additional workspace creation is available from the workspace switcher, and the creator becomes its Owner. Invitations are tied to one workspace and cannot be accepted into a different one by changing the active workspace.

Audit team changes#

DNSMigrator records invitation creation and revocation, invitation acceptance, role changes, member removal and workspace creation. The entries identify a target and initiating user ID in storage, but the current Activity table displays user-originated events as You rather than resolving teammate names. Read Activity log for that limitation.

Provider credential use is separately audited. If you grant Admin, that person can trigger provider reads and writes; review Credential security and keep provider credentials scoped independently of workspace roles.