# Teams, roles and permissions

> Invite members to a Falak organization, assign owner, admin, developer or viewer roles, and use teams, permissions, two-factor auth and the audit log.

Source: https://falak.sh/docs/guides/teams-and-roles/

Access in Falak is per **organization**. Each member has one **role**, and each role grants a fixed set of **permissions**. API tokens use the same permission names as abilities.

## Roles

| Role | Can |
|---|---|
| **Owner** | Everything, including deleting the organization and transferring ownership. Holds every permission. |
| **Admin** | Manage members, teams, credentials (cloud providers, git, DNS, backup storage), agents, terminal, recipes and every resource |
| **Developer** | Create and operate servers, sites, deployments, databases, processes, domains and templates |
| **Viewer** | Read-only access |

Owners are not invited; ownership is transferred. Invitations grant admin, developer or viewer.

## Invite members

1. Open **Settings → Members** and click **Invite**.
2. Enter the e-mail address and pick a role.
3. The invitee gets a link that is valid for **7 days**.

Change a member's role or remove them from the same page (permission `members.manage`).

![Settings → Members: organization members with their roles and pending invitations.](./_images/settings-members.png)

## Teams

A **team** is a named group of members (for example "Backend" or "On-call"), managed under **Settings → Teams** (`teams.manage`). Teams organize people; access is still decided by each member's role.

## Permissions

| Permission | Owner | Admin | Developer | Viewer |
|---|:-:|:-:|:-:|:-:|
| `alerting.view` | ✓ | ✓ | ✓ | ✓ |
| `alerting.manage` | ✓ | ✓ | | |
| `audit.view` | ✓ | ✓ | | |
| `builds.view` | ✓ | ✓ | ✓ | ✓ |
| `builds.manage` | ✓ | ✓ | ✓ | |
| `databases.view` | ✓ | ✓ | ✓ | ✓ |
| `databases.manage` | ✓ | ✓ | ✓ | |
| `databases.credentials.reveal` | ✓ | ✓ | ✓ | |
| `databases.restore` | ✓ | ✓ | | |
| `databases.storage.manage` | ✓ | ✓ | | |
| `deployments.view` | ✓ | ✓ | ✓ | ✓ |
| `deployments.create` | ✓ | ✓ | ✓ | |
| `deployments.rollback` | ✓ | ✓ | ✓ | |
| `deployments.manage` | ✓ | ✓ | ✓ | |
| `edge.view` | ✓ | ✓ | ✓ | ✓ |
| `edge.manage` | ✓ | ✓ | ✓ | |
| `edge.dns.manage` | ✓ | ✓ | | |
| `fleet.agents.manage` | ✓ | ✓ | | |
| `fleet.commands.view` | ✓ | ✓ | ✓ | ✓ |
| `insights.view` | ✓ | ✓ | ✓ | ✓ |
| `insights.manage` | ✓ | ✓ | ✓ | |
| `members.view` | ✓ | ✓ | ✓ | ✓ |
| `members.manage` | ✓ | ✓ | | |
| `network.view` | ✓ | ✓ | ✓ | ✓ |
| `network.manage` | ✓ | ✓ | ✓ | |
| `organization.update` | ✓ | ✓ | | |
| `organization.delete` | ✓ | | | |
| `processes.view` | ✓ | ✓ | ✓ | ✓ |
| `processes.manage` | ✓ | ✓ | ✓ | |
| `projects.view` | ✓ | ✓ | ✓ | ✓ |
| `projects.manage` | ✓ | ✓ | ✓ | |
| `providers.view` | ✓ | ✓ | ✓ | ✓ |
| `providers.manage` | ✓ | ✓ | | |
| `recipes.view` | ✓ | ✓ | ✓ | ✓ |
| `recipes.manage` | ✓ | ✓ | ✓ | |
| `recipes.run` | ✓ | ✓ | | |
| `servers.view` | ✓ | ✓ | ✓ | ✓ |
| `servers.create` | ✓ | ✓ | ✓ | |
| `servers.manage` | ✓ | ✓ | ✓ | |
| `servers.delete` | ✓ | ✓ | | |
| `ssh_keys.manage` | ✓ | ✓ | ✓ | |
| `sites.view` | ✓ | ✓ | ✓ | ✓ |
| `sites.create` | ✓ | ✓ | ✓ | |
| `sites.manage` | ✓ | ✓ | ✓ | |
| `sites.delete` | ✓ | ✓ | | |
| `sites.env.view` | ✓ | ✓ | ✓ | |
| `sites.env.manage` | ✓ | ✓ | ✓ | |
| `sites.commands.run` | ✓ | ✓ | ✓ | |
| `sites.compose.policy` | ✓ | ✓ | | |
| `source_control.view` | ✓ | ✓ | ✓ | ✓ |
| `source_control.manage` | ✓ | ✓ | | |
| `telemetry.view` | ✓ | ✓ | ✓ | ✓ |
| `telemetry.manage` | ✓ | ✓ | | |
| `templates.view` | ✓ | ✓ | ✓ | ✓ |
| `templates.manage` | ✓ | ✓ | ✓ | |
| `terminal.open` | ✓ | ✓ | | |
| `terminal.attach` | ✓ | ✓ | | |
| `terminal.control` | ✓ | ✓ | | |
| `terminal.recordings.view` | ✓ | ✓ | | |

Descriptions of each permission are in [Permissions reference](/docs/reference/permissions/).

## Two-factor authentication

Each user can enable TOTP two-factor authentication under **Settings → Two-factor auth**, with recovery codes. Enforcing 2FA for a whole organization is not available yet.

## Audit log

**Settings → Audit log** (`audit.view`) records sensitive actions: revealing variables, issuing install tokens, upgrading agents, changing domain settings, deleting organizations and more.

## Several organizations

A user can belong to several organizations and switch between them in the top bar. Create a new one with **⌘K → New organization**. API tokens are pinned to the organization they were created in.

## Next steps
