Skip to content
Databasezy

Teams and roles

Give people exactly the access they need

Viewers never see credentials, developers cannot delete, billing sees no instances. On Team and Enterprise, add project-scoped roles, team budgets, approvals for large or secure instances, and single sign-on.

Teams and roles, step by step

  1. Step 01

    Invite and assign roles

    Owner, admin, developer, read-only, billing, auditor or project-only. Each role is a tested permission set.

  2. Step 02

    Group into teams

    Teams own projects, carry a monthly budget and a cost centre, and have their own lead, developer, operator and viewer roles.

  3. Step 03

    Set policy

    Limit engines, regions, placements and sizes per team, and require approval above a threshold.

  4. Step 04

    Approve

    Requests over the policy wait for a lead. Approval creates the instance; every decision is audited with a reason.

What you get

  • Predefined org roles

    Seven roles from owner to auditor. On Team and Enterprise you can adjust what the predefined roles allow; the owner stays fixed.

  • Project-scoped access

    Give someone admin, developer or read-only on a single project instead of the whole org.

  • Team budgets

    Billing computes spend per team. Creations that would exceed a team's budget are refused unless approved.

  • SSO and SCIM

    OIDC or SAML connections, verified domains that can enforce SSO, and SCIM 2.0 provisioning of users and groups.

  • Service accounts and scoped keys

    Machine members with an API key and a role. They cannot sign in interactively, and keys can be limited to specific permissions.

  • Audit log

    Every control-plane action with actor and reason, exportable and streamable to your SIEM on Team and Enterprise.

Try it

shell
zb teams create --name platform --cost-centre CC-4410 --budget-cents 250000
zb teams add-member team_01J9... usr_01J9... --role operator
zb members invite [email protected] --role developer

zb approvals list --status pending
zb approvals approve apr_01J9... --reason "Q4 load test"

zb api-keys create --name ci --scope instances:read,backups:read

Plan availability

Generated from the same plan catalogue that billing and the API use.

  • Free

    $0 /mo
    Limited

    One seat (the owner) with API keys

  • Solo

    $25 /mo
    Limited

    One seat (the owner) with API keys

  • Team

    $599 /mo
    Included

    Unlimited members, SSO, SCIM, project and read-only roles

  • Enterprise

    Custom
    Included

    Unlimited members, SSO, SCIM, roles and subsidiaries

Solo is a single-seat plan. To invite collaborators, move the org to Team; extra members are included there.

Compare every plan on the pricing page

Questions

Who can see database credentials?

Owners, admins and developers can reveal them, once, and every reveal is audited. Two-factor authentication is optional (and required on Enterprise and BAA organizations). Read-only, billing and auditor roles never see them.

Can SSO be enforced?

Yes. Verify your email domain, then members at that domain must sign in through your identity provider. Owners are exempt so an org cannot lock itself out.

How long do approval requests last?

Seven days. Requesters see the status on the instance list, and every approval or denial is audited with the reason.

Do auditors use a seat?

No. Auditors and service accounts do not consume seats.

Create your first database

A free instance, no card. Upgrade when you outgrow it; nothing converts silently.