Invite your team
Add teammates and set the right role for each one.
You can invite teammates from the Settings → Team page. Each teammate gets an email with a sign-in link.
Roles
| Role | What they can do |
|---|---|
| OWNER | Everything. Manage billing, change plan, delete tenant. Usually one or two per account. |
| ADMIN | Same as Owner except can't change billing or delete the tenant. Can change PSA / Slack / integration settings, add users, set escalation policies. |
| MEMBER | Day-to-day operator. Can resolve alerts, view instances, open consoles. Can't change integration or billing settings. |
SUPER_ADMIN is Sikurd-internal only — that's us, not you.
Instance access restriction
For tenants on Pro+, you can restrict a Member to only see a subset of instances:
- Settings → Team.
- Click the member's row → Manage instance access.
- Toggle "Restrict to specific instances" and pick the instances they can see.
Restricted members:
- Only see those instances in the dashboard, instances list, alerts filter, calls page, etc.
- Don't appear in escalation policies for instances they can't see.
Note: Restricted access is the primary UI gate today. A small number of API endpoints still scope only by tenant (we're closing those in the next sprint). If you have a high-security need, keep the restricted member at OWNER discretion until that work lands.
Inviting someone
- Settings → Team → Invite member.
- Enter the email + name + role.
- (Optional) Toggle "Restrict instance access" and choose the instances.
- Send invite.
They get an email with a link that creates their account on first click. The link expires in 24 hours; you can re-send anytime from the Team page.
SSO
Microsoft 365 single sign-on is available on Pro+. Setup is a joint step between your M365 admin and our team — email help@sikurd.com to get it enabled.
Next
See your first alert
Trigger a test alert so you can verify routing end-to-end.