Security
Team & Permissions
Access is organization-first. Invite people under Settings → Members, assign a role (and optionally a team), then decide which teams own or can reach each project.
Project Ownership & Access is the owning team plus team access — not an invite-by-email form. API automation uses a token from Settings → API tokens (prefix kbr_pat_), not Account Settings → API Keys.
Members page
Settings → Members has four tabs: Users, Invitations, Teams, and Roles.
Users
People already in the organization, with their roles and team memberships. Remove a member here to drop their org access.
Invitations
Invite member sends an email link. Choose a role and an optional team (or leave team empty for tenant-wide).
Teams
Group members, then use those teams on project Ownership & Access so only the right teams can view and deploy.
Roles
Built-in admin, member, and guest, plus custom roles you create. Permissions are per resource (apps, pipelines, tokens, audit, and so on).
Built-in roles
admin
Built-in organization role. Can manage members, teams, roles, and most project operations.
member
Built-in organization role for people who deploy and operate apps without owning org settings.
guest
Built-in organization role with a narrower permission set. Use when someone only needs limited access.
Members
Alex Chen
alex@acmecorp.com
Sam Rivera
sam@acmecorp.com
Taylor Kim
taylor@acmecorp.com
Project access and org extras
Ownership & Access
On the project: owning team, plus which teams can view and deploy. Invite new people from org Members first, then put them on a team this project allows.
API tokens
Settings → API tokens. Tokens are scoped to the current organization. Use them as Bearer tokens against api.stackblaze.cloud/api.
Audit trail
Organization Settings / Security (/security) lists audit history. It is not an IP allowlist. Requires audit read permission. Export CSV is on that page.
SSO
Enterprise orgs can add Settings → Single Sign-On (SAML / OIDC). Members on a verified domain sign in through that provider.
Step by step
Invite someone to the organization
Go to Settings → Members → Invite member. Enter their email, pick a role, and optionally a team. StackBlaze emails a link to join. Pending invites stay on the Invitations tab until they accept, expire, or you revoke them.
Give a project to a team
Project settings → Ownership & Access sets the owning team and which other teams can view and deploy into that project. That screen is not invite-by-email — invitations always start at org Members.
Create or adjust a role
Settings → Members → Roles. Built-in admin, member, and guest cannot be edited. Custom roles set permissions for apps, pipelines, accounts, settings, security, tokens, audit, console, logs, and reboot.