What can each role actually do?
Owner has full control of the organisation and its sub-accounts, including members, API keys, sites and payment methods. Billing Manager sees invoices, subscriptions, payment methods and plans, with no site access. Developer manages sites and API keys and handles tickets, with no billing or member control. Read-only can view members, sites, billing, plans, tickets and the audit log without changing anything.
Can I give someone access to just one site?
Not as a per-site setting yet — narrowing a single membership to specific sites is a planned refinement. Today you achieve the same separation with the tenancy tree: put those sites in a child organisation and give the person a role there. Because roles are granted per organisation, that access does not carry over to anything else in your account.
Are API keys tied to individual team members?
No — API keys are issued per organisation, with granular scopes tied to the same RBAC permissions, and separate sandbox and live modes. Use them as service credentials for integrations, CI or Terraform, and use memberships for people. Only a hash of each key is stored, each key records when it was last used, and any key can be revoked on its own.
Can a developer push changes to a live site?
The Developer role covers viewing and provisioning sites, restarting services, purging caches, managing API keys and handling tickets. It does not carry publishing rights over a live site, so if you want someone to be able to promote changes, that access needs to sit with an owner. Roles are per organisation, so you can hold a different one on a different account.
Do you support SSO for our company directory?
Yes. Identity runs on Keycloak with OIDC and SAML, so SAML single sign-on is available for enterprise and agency customers alongside magic-link login, email and password, social providers, passkeys and TOTP two-factor authentication, which is enforced by policy. One session covers the dashboard, the public site and knowledge base, and support tickets.
How do I know who changed something?
Every privileged action is written to an append-only audit log recording the actor, the action, the target, supporting evidence and the IP address. Reading it is a permission in its own right, held by both the Owner and Read-only roles, so an account owner and an auditor can review the same history.
Does adding team members change what I pay?
Plans are priced by hosting capacity rather than by people. On the Footprint-Free line, for example, all 42 tiers share exactly the same entitlement set and differ only by the number of sites they allow. Pricing is always rendered from the live catalogue, in your currency, so what you see on the pricing page is what is actually charged.
Can I try this before committing?
Yes. The Footprint-Free trial runs for 7 days, needs no card details and covers up to 5 sites, so you can set up your organisation, invite your team and test the roles against real work before you pay anything. There is a 30-day money-back guarantee behind the paid plans.