Theme
Your team and their roles
Team lists the people who can sign in to the Portal and manage your account.
These are not the accounts your users transfer files with. Those are on Users.
The three roles
| Role | What it holds |
|---|---|
| Admin | Everything: sites, users, billing, the team and support access |
| Accounting | The money side: buying sites, plans, payment details and invoices. No site configuration |
| Tech | The technical side: sites, users, connectors and settings. Nothing that spends money |
The split the roles encode is the money path against the technical path. An accounting member can never change how a site is configured. A tech member can never cause a charge, a purchase or a plan change.
Every role, including tech, can read the account Activity log and the Service level and Tamper evidence pages. Those carry action metadata, never file content, and transparency inside your own team is deliberate.
A full capability by capability table is in Roles and capabilities.
Site scoping
Accounting and tech members can be limited to specific sites.
- Leave the scope as All sites, including ones created later for an unrestricted member.
- Or check specific sites. A scoped member's world is their scope: site lists and the dashboard show only those sites, and a site outside the scope answers exactly as a site belonging to somebody else would.
Admin is always account wide. There is no scoped admin.
Creating a new site requires account wide reach, so it needs an admin or an unscoped accounting member.
Inviting somebody
- Choose Invite someone.
- Enter their email address, pick a role, and set a scope if the role allows one.
- Choose Send invitation.
They receive an email with a link to create their own sign in. Nothing is created until they accept. Invitations expire after 7 days; you can resend or revoke a pending one at any time.
An email address that already has an SFTP.cloud account cannot be invited. One person, one account, one organization.
What happens when they accept
They choose their own name and password, and are then taken straight to authenticator setup, which is mandatory. See Secure your sign in.
Changing somebody's role or scope
Open the member and edit them.
Saving signs that member out everywhere. They continue with the new role at their next sign in. That is deliberate: a role change that only applies to future sessions is not a role change.
Removing somebody
Choose Remove. They are signed out everywhere and lose access immediately.
Sites, users and billing are unaffected. Removing a team member never touches anything they created.
The guard that cannot be turned off
Your account must always keep at least one active admin. Removing the last one, or changing their role, is refused.
Two habits worth adopting
Keep at least two admins. Support cannot reset a locked out colleague's second factor without an active support grant, and only somebody signed in with the admin role can create one. Two admins turns a hard problem into a five minute one.
Give tech members the tech role. Somebody who configures users and connectors all day does not need the ability to cancel your subscription, and the role costs nothing to use.