Team & Permissions

Security

Team & Permissions

5 min readUpdated August 2026

Access is organization-first. Invite people under Settings → Members, assign a role (and optionally a team), then decide which teams own or can reach each project.

Project Ownership & Access is the owning team plus team access — not an invite-by-email form. API automation uses a token from Settings → API tokens (prefix kbr_pat_), not Account Settings → API Keys.

A member is invited from the Members page, a role is picked from admin, member, or guest, and the pending invite lands with a 7-day expiry.

Members page

Settings → Members has four tabs: Users, Invitations, Teams, and Roles.

Users

People already in the organization, with their roles and team memberships. Remove a member here to drop their org access.

Invitations

Invite member sends an email link. Choose a role and an optional team (or leave team empty for tenant-wide).

Teams

Group members, then use those teams on project Ownership & Access so only the right teams can view and deploy.

Roles

Built-in admin, member, and guest, plus custom roles you create. Permissions are per resource (apps, pipelines, tokens, audit, and so on).

Built-in roles

admin

Built-in organization role. Can manage members, teams, roles, and most project operations.

Built-in

member

Built-in organization role for people who deploy and operate apps without owning org settings.

Built-in

guest

Built-in organization role with a narrower permission set. Use when someone only needs limited access.

Built-in

Members

Invitations
Invite member
AC

Alex Chen

alex@acmecorp.com

admin
SR

Sam Rivera

sam@acmecorp.com

member
TK

Taylor Kim

taylor@acmecorp.com

guest

Project access and org extras

Ownership & Access

On the project: owning team, plus which teams can view and deploy. Invite new people from org Members first, then put them on a team this project allows.

API tokens

Settings → API tokens. Tokens are scoped to the current organization. Use them as Bearer tokens against api.stackblaze.cloud/api.

Audit trail

Organization Settings / Security (/security) lists audit history. It is not an IP allowlist. Requires audit read permission. Export CSV is on that page.

SSO

Enterprise orgs can add Settings → Single Sign-On (SAML / OIDC). Members on a verified domain sign in through that provider.

Step by step

01

Invite someone to the organization

Go to Settings → Members → Invite member. Enter their email, pick a role, and optionally a team. StackBlaze emails a link to join. Pending invites stay on the Invitations tab until they accept, expire, or you revoke them.

02

Give a project to a team

Project settings → Ownership & Access sets the owning team and which other teams can view and deploy into that project. That screen is not invite-by-email — invitations always start at org Members.

03

Create or adjust a role

Settings → Members → Roles. Built-in admin, member, and guest cannot be edited. Custom roles set permissions for apps, pipelines, accounts, settings, security, tokens, audit, console, logs, and reboot.