Members
The Members page is where you manage who can do what in your organization. It lives under Settings → Members (avatar dropdown in the top-right of the Console). Each organization has its own members list — switching organizations changes who you see here.
Roles #
Depfloy has five built-in roles. Pick the role that matches what someone needs to do; do not give a more powerful role “just in case”. You can change a member’s role any time.
Owner #
Full access to all organization settings, servers, and team members. The Owner is the only role that can transfer ownership and delete the organization. Each organization has exactly one Owner.
Admin #
Full access to the organization, except managing or assigning Owner roles. Admins can do everything Owners can except transfer ownership or delete the organization itself.
Manager #
Manages servers and team, but not billing or organization settings. Managers can create new servers, transfer them, invite teammates, and manage projects — but they cannot view or change billing or organization-wide settings, and cannot configure or restore backups.
Developer #
Full access to servers and sites, but can’t create new servers. Developers can deploy, manage existing servers, run commands, edit project settings, manage SSL and domains — and can delete a server or project they have access to. They cannot create new servers, manage members, touch billing, or restore and configure backups.
Viewer #
View all servers, sites, and sensitive data without making changes. Viewers can see deployment history, view logs, and inspect configuration. They cannot trigger deployments or change anything.
Capability summary #
Use the Compare roles button on the Members page for a side-by-side capability table. Highlights:
| Capability | Owner | Admin | Manager | Developer | Viewer |
|---|---|---|---|---|---|
| View servers, projects, deployments, logs | ✓ | ✓ | ✓ | ✓ | ✓ |
| View DNS zones and records | ✓ | ✓ | ✓ | ✓ | ✓ |
| Trigger deployments | ✓ | ✓ | ✓ | ✓ | — |
| Update server settings | ✓ | ✓ | ✓ | ✓ | — |
| Create and remove databases | ✓ | ✓ | ✓ | ✓ | — |
| Manage projects (SSL, env, domains, jobs) | ✓ | ✓ | ✓ | ✓ | — |
| Install applications from the catalog | ✓ | ✓ | ✓ | ✓ | — |
| View health checks and heartbeats | ✓ | ✓ | ✓ | ✓ | — |
| Cancel a running deployment | ✓ | ✓ | ✓ | ✓ | — |
| Roll back to an earlier deployment | ✓ | ✓ | ✓ | ✓ | — |
| Delete servers and projects | ✓ | ✓ | ✓ | ✓ | — |
| View backups and history | ✓ | ✓ | ✓ | ✓ | ✓ |
| Create and edit backup schedules | ✓ | ✓ | — | — | — |
| Restore, download and delete backups | ✓ | ✓ | — | — | — |
| Reveal a server root password | ✓ | ✓ | — | — | — |
| Open, join and end terminal sessions | ✓ | ✓ | — | ✓ | — |
| Let an MCP assistant use a terminal | ✓ | If allowed | — | If allowed | — |
| Choose which roles’ assistants can use a terminal | ✓ | — | — | — | — |
| Create new servers | ✓ | ✓ | ✓ | — | — |
| Transfer servers between organizations | ✓ | ✓ | ✓ | — | — |
| Create, turn on/off, and delete health checks and heartbeats | ✓ | ✓ | ✓ | — | — |
| Edit DNS records and apply guided setups | ✓ | ✓ | ✓ | — | — |
| Invite, edit, and remove members | ✓ | ✓ | ✓ | — | — |
| Manage API tokens | ✓ | ✓ | ✓ | — | — |
| View the activity log | ✓ | ✓ | ✓ | — | — |
| Manage server provider credentials | ✓ | ✓ | — | — | — |
| Connect or remove third-party integrations | ✓ | ✓ | — | — | — |
| View / update organization settings | ✓ | ✓ | — | — | — |
| Create a new organization | ✓ | ✓ | — | — | — |
| Transfer ownership | ✓ | — | — | — | — |
| Delete the organization | ✓ | — | — | — | — |
Three rows are worth pausing on, because the role descriptions above read wider than they are:
- Backups stop at Admin. Everyone can see them; creating a schedule, restoring and deleting are Owner and Admin only. A Manager who administers servers still cannot restore one — a restore overwrites data, and it sits with the roles that answer for the account.
- An assistant’s terminal is the Owner’s call. Admin and Developer can open terminals in the browser, but their MCP assistants can use one only after the Owner allows that role under Configuration → MCP → Connections → Terminal access for assistants. See Terminal Sessions.
- Deleting is not gated the way creating is. A Developer cannot create a server but can delete one they have access to. If that is wider than you want for someone, limit them to specific servers with a scope rather than changing their role.
Creating an organization and renaming one — or changing its avatar — both count as organization settings, so they stop at Admin. A Manager keeps full member management; the Edit entry on an organization is what they no longer see.
Team members need the Business plan #
Inviting a teammate and changing someone’s role require the Business plan.
- On Starter and Pro, the invite and role-change actions are unavailable.
- Members who are already in the organization keep their access — nothing is taken away from anyone on a plan change.
- Removing a member works on every plan, so an account is never stuck unable to tidy up its own access.
The Members page stays visible on every plan and says what the feature is and how to get it. Hiding it from the person who would decide to upgrade would be backwards.
Limiting access to specific servers or projects #
Beyond a role, every member except the Owner can be scoped — limited to a subset of the organization’s servers or projects.
- Server scope — the member can only see and act on the servers you select.
- Project scope — the member can only see and act on the projects you select.
- Project access is built on top of server access: a member needs access to a project’s server before project access can be granted. If you remove a server from someone’s scope, their project scope on that server is removed automatically.
The Owner is unscoped because ownership is the permanent organization-wide role; transferring ownership is a separate action.
Invite a new member #
Two invite flows depending on whether the person already belongs to another organization in your Depfloy account:
- Invite member — for someone outside your Depfloy account. Enter their email; they receive an invitation, create an account, and are added to the organization with the role and scope you chose.
- Add existing user — for someone who already belongs to another organization in your Depfloy account. The list shows users not yet in the current organization, with an “in N orgs” badge so you know who is where. They are added immediately, without a separate invitation email.
Both flows let you set the role and scope at invite time. You can change either later from the member’s row.
How an invitation is accepted #
The invited person opens the acceptance screen from the link in the invitation email. That link is what proves the invitation is theirs, so the screen cannot be filled in without following it.
If an account already exists for the invited address, the screen does not create a second one — it says so and the person signs in with the account they have. The invitation stays pending in that case, so you can cancel or resend it from the Members screen.
Edit a member #
Click a member’s row to edit their role or scope. Changes take effect on the member’s next page load — no sign-out required.
Remove a member #
Click Remove next to a member to remove them from the current organization. The user account itself is not deleted; if they belong to other organizations in your Depfloy account, those memberships are unaffected.
Migration notes #
If you are reading this after upgrading from an earlier version:
- Members who used to have the legacy “member” role are now Viewers. Re-assign them to a more appropriate role if they were doing more than viewing.
- Members who used to have “Deployer” are now Developers. The capability set is unchanged; only the name changed.
- The new Manager role sits between Admin and Developer — it is a good fit for someone who needs to manage the team and infrastructure but not billing or organization settings.