Teams and access control
When more than one person works in dagweave, a team is how you share workflows and control who can do what. Teams and the access controls on this page are part of a paid plan.
Teams and roles
Section titled “Teams and roles”A team owns workflows and is the unit dagweave bills. Every account starts with its own personal team, and you invite people into a shared team to work together.
Each member has a role, and the roles stack from least to most access:
- Viewer can read.
- Editor can read, create, edit, and run workflows.
- Admin can do everything an editor can, plus delete workflows and manage members.
- Owner can do everything an admin can, plus manage billing.
An admin or owner invites people by email and picks the role they join with. The invite link stays valid for seven days. You can change a member’s role later, and a team always keeps at least one owner.
Fine-grained access
Section titled “Fine-grained access”Roles set what a member can do across the whole team. When you need to be more precise, dagweave supports two finer controls:
- Per-object sharing. Grant one teammate view or edit access to a single workflow, connector, or template, without changing their team role. You can only share within the team that owns the resource.
- Relationship-based access control. dagweave runs its permission checks through a relationship-based model (built on OpenFGA), so access follows the relationships between users, teams, folders, and workflows rather than a flat role.
Multi-factor sign-in
Section titled “Multi-factor sign-in”Accounts can add a second factor at sign-in:
- An authenticator app using a time-based one-time code (TOTP).
- Passkeys using WebAuthn, and you can register more than one.
When you enrol, dagweave gives you ten single-use recovery codes to get back in if you lose your factor. An account counts as protected once it has at least one confirmed factor.
Audit log
Section titled “Audit log”Every team has an append-only audit log. It records who did what: sign-ins and sign-outs, multi-factor changes, workflow create, edit, delete, publish, and run, team and member changes, and billing changes. Entries cannot be edited or deleted.
You can filter the log by action, by actor, by outcome, and by a time window, and export the results as CSV.