Hosted edition
Users and Roles
Every ORDSwatch account (tenant) can have multiple team members, each with one of three roles.
Roles
| Role | Can do |
|---|---|
| Viewer | See instances, health, logs, history, alert config, deploy templates and history. Read-only everywhere. |
| Operator | Everything a Viewer can, plus start/stop/restart instances, trigger config deploys, and configure alerts. |
| Admin | Everything an Operator can, plus invite/remove users, change roles, and manage billing/plan. |
The account's first user (created at signup) is always an Admin.
Inviting a teammate
Admins only:
- Go to Users → Invite User
- Enter their email and choose a role (Viewer, Operator, or Admin)
- They receive an email invitation to set a password and log in
Changing or removing a user's access
Users → (user) → Edit to change their role, or Remove to revoke their access entirely. Removing a user doesn't affect the audit trail of actions they already took (deploy history, etc. still show who did what).
Authentication
Version 1 of ORDSwatch uses simple username/password login, scoped to your account, with optional Duo multi-factor authentication available on Professional and Enterprise plans (enabled per-user from your profile). Single sign-on (LDAP, SAML, OIDC) is on the roadmap as a future Enterprise-tier feature — it is not yet available per-account in the hosted product.
Related
- Billing and Plans — only Admins can manage this
How many users? Free is a single user. Starter includes up to 3 admins and operators, Professional up to 10, and Enterprise 20 (then $5/month each). Viewers are unlimited from Starter up — see Billing and Plans.