# Team access and security

> Manage workspaces, members, roles and site access for your analytics team, and secure sign-in with SSO, SCIM, two-factor authentication and an audit log.

## Workspaces and members

A **workspace** owns sites, members, billing, API tokens and webhooks.
Everyone in it is a **member** with one **role** and access to **all
sites** or **selected sites**.

- **Invite** from **Workspace settings → Members**: enter up to 50 email
  addresses, then choose a role and site access. Invitations are emailed
  and expire after 14 days. You can revoke pending ones.
- **Change role** or **site access** at any time. "All sites" includes
  sites added later. You can't change your own access, or give someone a
  role or sites beyond your own.
- **Remove** a member: their API tokens for this workspace stop working
  immediately. Members can also leave on their own.
- **Transfer ownership** to another member (owners only). The previous
  owner becomes an admin. The owner can't be removed or leave before
  that.

Inviting, changing and removing members need the `members.manage`
permission (see [Roles & permissions](/docs/teams/roles)). Per-site
access can also be managed from a site's **Access** tab.

The Free plan allows 3 members, and pending invitations count toward
that limit. Paid plans are unlimited.

Members and invitations are REST resources under
`/workspaces/<workspace id>/members` and
`/workspaces/<workspace id>/invitations`, and MCP tools named `members_*`
and `invitations_*`. The [API reference](/docs/api) lists every input.

## In this section

- [Roles & permissions](/docs/teams/roles), including custom roles.
- [Single sign-on](/docs/teams/sso) with guides for
  [Okta](/docs/teams/sso-okta), [Microsoft Entra ID](/docs/teams/sso-entra-id),
  [Google Workspace](/docs/teams/sso-google-workspace) and
  [JumpCloud](/docs/teams/sso-jumpcloud).
- [SCIM provisioning](/docs/teams/scim).
- [Two-factor authentication](/docs/teams/two-factor).
- [Audit log](/docs/teams/audit-log).

## Workspace security settings

**Workspace settings → Security** holds the sign-in rules for everyone
in the workspace. Changing them needs the `workspace.manage` permission,
which the Owner and Admin roles have.

| Setting | Options | Plan |
|---|---|---|
| **Require two-factor authentication** | On or off | Business |
| **Allowed login methods** | Email and password, Email login link, Passkey, Google, GitHub, SSO (SAML/OIDC) | All |
| **Sign members out after** | No limit, 8 hours, 24 hours, 7 days or 30 days | All |
| **IP allowlist** | IP addresses and CIDR ranges, IPv4 or IPv6 | Business |
| **Support access** | On or off, for 7 days at a time | All |

- **Require two-factor authentication.** Members without an
  authenticator app or a passkey are sent to set one up before they can
  open the workspace. See
  [Two-factor authentication](/docs/teams/two-factor#enforce-it-for-everyone).
- **Allowed login methods** apply to every member, and at least one
  method must stay selected. The owner can always log in with a password
  or a passkey, so a login rule can't lock the owner out. Someone who
  belongs to several workspaces can use only the methods that all of
  them allow. When [SSO](/docs/teams/sso) is enforced, members sign in
  through SSO only.
- **Sign members out after** ends a session that many hours after the
  member signed in, however active they are. Someone who belongs to
  several workspaces gets the shortest lifetime among them.
- **IP allowlist.** Only the listed addresses can open the workspace in
  the app or use its API tokens. Put one entry per line, such as
  `203.0.113.0/24` or `2001:db8::/32`. An empty list allows any address.
  The list must include the address you are saving from (the page shows
  it), so you can't lock yourself out.
- **Support access** lets Privatus Analytics support view the workspace for 7 days
  from the time you save. Support staff cannot see your workspace unless
  you allow it. Turn it off to end access at once. Access is read-only
  and every view is written to the
  [audit log](/docs/teams/audit-log#support-access).

> **Note:** On a plan below Business the two Business settings are shown
> switched off. If a workspace moves to a lower plan, its 2FA requirement
> and IP allowlist are kept but stop applying until it is back on
> Business.

Security settings are a REST resource at
`/workspaces/<workspace id>/security` (`GET` to read, `PATCH` to change)
and the MCP tools `workspace_security_get` and
`workspace_security_update`. Over the API, `session_ttl_hours` takes any
whole number of hours up to 2,160 (90 days), and `0` means no limit. The
[API reference](/docs/api) lists every input.
