---
title: Members & roles
description: Owner, admin and member roles and what each can do, invitations, personal settings, 2FA, API keys, OAuth consent and multiple workspaces.
canonical: https://watchfor.io/docs/organization
---

# Members & roles

Owner, admin and member roles and what each can do, invitations, personal settings, 2FA, API keys, OAuth consent and multiple workspaces.

Everything in WatchFor lives inside an **organization** (also called a
workspace) — your monitors, alert rules, channels, incidents, status pages,
API keys and billing. People join an organization with a **role** that
controls what they can do. Organization settings live under **Settings** in
the sidebar (General, Members, Notifications, API keys, Activity log,
Subscription); your personal settings are under your avatar → **Settings**.

## Roles

	- [Owner](#): Full control. Everything an admin can do, plus deleting the organization. Usually the person who created it.
	- [Admin](#): Runs the organization day to day: monitors, alert rules, channels and contacts, status pages, maintenance, on-call, billing, members, API keys, report emails, the activity log.
	- [Member](#): Works incidents: sees everything, acknowledges, writes internal notes and post-mortems, takes on-call shifts — without changing monitors, alerting setup, status pages or organization settings.

What each role can do today:

| Action | Owner | Admin | Member |
| --- | --- | --- | --- |
| View monitors, incidents, dashboards, reports, alert rules, channels, contacts, contact groups and status pages | ✓ | ✓ | ✓ |
| Acknowledge incidents, write [internal notes](/docs/alerting/internal-notes) | ✓ | ✓ | ✓ |
| Write [post-mortems](/docs/alerting/postmortems) | ✓ | ✓ | ✓ |
| Send a test notification to a channel or through a monitor's route | ✓ | ✓ | — |
| Organization notification preferences and settings | ✓ | ✓ | — |
| Create, edit, pause, resume, delete monitors; run a check now; mute alerts; import from other tools | ✓ | ✓ | — |
| Manage [alert rules](/docs/alerting), [notification channels](/docs/notifications), [contacts and contact groups](/docs/notifications/contact-groups) | ✓ | ✓ | — |
| Create, edit and delete [status pages](/docs/status-pages), their components and announcements | ✓ | ✓ | — |
| [Resolve incidents manually](/docs/alerting/resolving#manual-resolve), mark as maintenance | ✓ | ✓ | — |
| Publish or delete post-mortems | ✓ | ✓ | — |
| [Maintenance windows](/docs/monitors/maintenance), [on-call schedules and escalation policies](/docs/alerting/on-call) | ✓ | ✓ | — |
| [Report email](/docs/reports) cadences and recipients | ✓ | ✓ | — |
| Invite and remove members, change roles | ✓ | ✓ | — |
| Billing: change plan, invoices, payment method | ✓ | ✓ | — |
| API keys (create, rename, revoke — members don't see the list) | ✓ | ✓ | — |
| View the [activity log](/docs/organization/activity-log) | ✓ | ✓ | — |
| Delete the organization | ✓ | — | — |

Members are not left guessing: an action they may not take is **shown but
disabled**, with an *Owners and admins only* tooltip — organization name and
branding, notification preferences, Create monitor and Import, new
maintenance windows and on-call schedules. Two things are hidden rather than
disabled, because there is nothing useful behind them: **Settings → API
keys** (a member opening `?tab=api-keys` lands on General) and **Settings →
Activity log**, which shows an *Owners and admins only* notice if a member
follows a direct link. Acknowledging incidents, writing internal notes and
drafting post-mortems stay open to members — that is the point of the role.

## Inviting people

Invite teammates from **Settings → Members** by email and pick their role.
The invitee gets an email; accepting it creates their membership (and their
account, if they're new). Pending invitations count toward your plan's
**member limit** together with current members, so you're told before you
run out of seats — the limit depends on your plan (see [pricing](/pricing));
there are no per-seat fees.

An invitation that never arrived can be **re-sent** from the **⋯** menu on
its row in *Pending invitations* — the same link goes out again and the
activity log records the resend. Revoking an invitation, removing a member
and leaving an organization all ask you to confirm first, naming the person
or the email address, because each one takes access away immediately.

Roles can be changed later from the same page, and every invitation,
re-sent invitation, revoked invitation, join, role change (attributed to the
person who made it) and removal is written to the
[activity log](/docs/organization/activity-log).

## Switching organizations

People can belong to **any number of organizations** and switch between them
from the organization picker. The picker shows each organization's health at
a glance — monitor count and any firing incidents — so you can jump to the
one that needs you. If you belong to only one, you land straight in it.

**Deep links work from a cold start.** A link in an alert email, a Slack
message or a bookmark — an incident, a monitor, a filtered list — opens the
page it points to right after you sign in, without a detour through the
dashboard home; the workspace is picked for you when the link belongs to
your only organization or the one you used last. A link to something that no
longer exists (or that you are not a member of) gives one consistent screen
inside the dashboard: *This monitor doesn't exist or you don't have access*,
with a way back — never a blank page or a silent redirect.

## Multiple workspaces

Every account includes **one free workspace** — normally the one created at
sign-up. You can create more (one per client, per company, per environment),
and each additional workspace needs **its own plan**:

- A new extra workspace starts **locked** — it can't run monitors or use the
  toolbox until a plan is chosen in its **Settings → Subscription** (a coupon
  code works too). You can also delete it from there if you created it by
  mistake.
- Your existing free workspace is never affected — you don't have to upgrade
  it to add a paid workspace next to it.
- Memberships don't count: you can be invited into any number of other
  organizations regardless of what you own.
- If your free allowance is no longer in use (you deleted or upgraded that
  workspace), a locked workspace offers **"Use my free workspace allowance
  here"** and becomes your free one.

You can own up to 10 workspaces; if you genuinely need more,
[contact us](/contact).

## Personal settings

Under your avatar → **Settings**:

- **Profile** — name, avatar, email, and your **timezone and time format
  (12-hour or 24-hour)**. Every time shown in the dashboard — check results,
  incident timelines, the activity log — follows these preferences.
- **Security** — change your password (or set one if you signed up with
  Google), turn on **two-factor authentication** with an authenticator app
  (TOTP), and manage connected sign-in providers.
- **Sessions** — see every active session with its device and browser, and
  sign out the ones you don't recognize.
- **Delete account** — removes your user account. Hand organizations you own
  to another owner (change their role to owner) or delete them first.

Sign-in options are email + password and **Google**. Two-factor
authentication is per user and is enforced on every sign-in once enabled.

## Inbox and in-app notifications

The bell in the top bar and the **Inbox** page (sidebar → Inbox) hold your
in-app notifications for the active workspace: incidents opening,
being acknowledged and resolving, what's new in WatchFor, service notices,
and — as they are rolled out — maintenance and report events.

- **Bell** — the eight most recent notifications. Clicking one marks it read
  and opens it in the Inbox, where the full text is readable and an **Open**
  button leads to what it is about (the changelog entry, an incident…).
  **Read all** and **Clear** act on your whole inbox, not just the eight
  shown; on the Inbox page **Clear all** asks you to confirm first.
- **Inbox** — a list on the left, the full message on the right. Incident
  rows are badged by severity — red **Down** for critical, amber
  **Degraded** for warning — and say how an incident ended: *Recovered
  after 12m* for an automatic recovery, *Resolved manually by …* when a
  person closed it. The monitor's target is on its own line, and a
  heartbeat monitor shows its name there rather than its ping URL. Filter by
  Unread or category, search, and use the keyboard: <kbd>j</kbd>/<kbd>k</kbd>
  move, <kbd>↵</kbd> opens the target, <kbd>u</kbd> toggles unread,
  <kbd>e</kbd> dismisses. Every notification has a link you can share with a
  teammate (`?n=…`). The full list of dashboard shortcuts is in
  [Keyboard shortcuts](/docs/reference/keyboard-shortcuts).
- **Read and dismissed are yours alone.** Marking something read or clearing
  your inbox never changes what other members see.
- **Preferences** — Settings → Notifications lets each member choose which
  kinds land in their bell and Inbox (incidents, maintenance windows,
  reports, what's new, system messages). A switch applies immediately, also
  to what was posted earlier, and switching it back on brings those back.
  Alert channels (email, Slack, PagerDuty…) are separate — see
  [Notifications](/docs/notifications).

## API keys

Owners and admins create API keys under **Settings → API keys** for scripts,
CI, the SDKs and CLI, and MCP clients configured by hand:

- Keys look like `wf_live_…`, belong to exactly one organization, and are
  shown **once** at creation (they're stored hashed).
- Each key has a fixed **scope** — `read` (every GET endpoint and read-only
  tools) or `write` (read plus create, update, delete, acknowledge, resolve)
  — and an optional **expiry**, as a number of days or an exact date and
  time.
- Keys can be **renamed** later; the name is what the activity log shows.
- An organization can hold up to **20 active keys**; revoke unused ones.
  Revocation is instant, and the dashboard shows each key's last use.
- Creation, renaming and revocation are logged, and everything a key does is
  attributed to it in the activity log as `API key: <name>`.

Full details: [API authentication](/docs/api/authentication).

## Connecting AI agents (OAuth 2.1)

MCP clients that support the MCP authorization flow (Claude, Cursor and
others) don't need a hand-made key. When such a client connects to
`https://watchfor.io/api/mcp`, WatchFor opens a **consent screen** in your
browser where you sign in, pick the organization and approve the scopes the
client asked for (`read`, `write`). The client then receives short-lived
access tokens (with refresh) that act with your membership's permissions.
See [OAuth 2.1](/docs/api/authentication#oauth-21) and the
[MCP server](/docs/api/mcp) pages.

## Deleting an organization

Owners can delete an organization from **Settings → General → Danger Zone**.
This is irreversible: monitors are removed from the checking fleet, and the
organization's data — monitors, incidents,
alert rules, channels, status pages (their public URLs stop resolving),
maintenance windows, on-call schedules, post-mortems, API keys and activity
log — is deleted. Cancel an active subscription and download any invoices
you need before deleting.

## Multi-tenant by design

Each organization's data is fully isolated. Monitors, incidents and settings
are always scoped to the organization you're working in, and an API key or
OAuth token can only ever see the organization it was issued for.

> **Also via API**
>
> `GET /v1/me` tells you which organization and scope a key or token has;
> `GET /v1/plan` returns the organization's plan and limits — see
> [Plan & usage](/docs/api/plan).

---

Canonical page: https://watchfor.io/docs/organization · All docs: https://watchfor.io/docs · Site guide: https://watchfor.io/llms.txt
