Teams and roles
Give people exactly the access they need
Viewers never see credentials, developers cannot delete, billing sees no instances. On Team and Enterprise, add project-scoped roles, team budgets, approvals for large or secure instances, and single sign-on.
How it works
Teams and roles, step by step
- Step 01
Invite and assign roles
Owner, admin, developer, read-only, billing, auditor or project-only. Each role is a tested permission set.
- Step 02
Group into teams
Teams own projects, carry a monthly budget and a cost centre, and have their own lead, developer, operator and viewer roles.
- Step 03
Set policy
Limit engines, regions, placements and sizes per team, and require approval above a threshold.
- Step 04
Approve
Requests over the policy wait for a lead. Approval creates the instance; every decision is audited with a reason.
What you get
-
Predefined org roles
Seven roles from owner to auditor. On Team and Enterprise you can adjust what the predefined roles allow; the owner stays fixed.
-
Project-scoped access
Give someone admin, developer or read-only on a single project instead of the whole org.
-
Team budgets
Billing computes spend per team. Creations that would exceed a team's budget are refused unless approved.
-
SSO and SCIM
OIDC or SAML connections, verified domains that can enforce SSO, and SCIM 2.0 provisioning of users and groups.
-
Service accounts and scoped keys
Machine members with an API key and a role. They cannot sign in interactively, and keys can be limited to specific permissions.
-
Audit log
Every control-plane action with actor and reason, exportable and streamable to your SIEM on Team and Enterprise.
Try it
zb teams create --name platform --cost-centre CC-4410 --budget-cents 250000
zb teams add-member team_01J9... usr_01J9... --role operator
zb members invite [email protected] --role developer
zb approvals list --status pending
zb approvals approve apr_01J9... --reason "Q4 load test"
zb api-keys create --name ci --scope instances:read,backups:readPlan availability
Generated from the same plan catalogue that billing and the API use.
- Limited
Free
$0 /moOne seat (the owner) with API keys
- Limited
Solo
$25 /moOne seat (the owner) with API keys
- Included
Team
$599 /moUnlimited members, SSO, SCIM, project and read-only roles
- Included
Enterprise
CustomUnlimited members, SSO, SCIM, roles and subsidiaries
Solo is a single-seat plan. To invite collaborators, move the org to Team; extra members are included there.
Questions
Who can see database credentials?
Owners, admins and developers can reveal them, once, and every reveal is audited. Two-factor authentication is optional (and required on Enterprise and BAA organizations). Read-only, billing and auditor roles never see them.
Can SSO be enforced?
Yes. Verify your email domain, then members at that domain must sign in through your identity provider. Owners are exempt so an org cannot lock itself out.
How long do approval requests last?
Seven days. Requesters see the status on the instance list, and every approval or denial is audited with the reason.
Do auditors use a seat?
No. Auditors and service accounts do not consume seats.
Related features
-
Spend cap
Usage-based billing with a spend cap that is on by default for Solo, and a monthly limit you set.
Learn more about Spend cap -
API and MCP
A REST API with an OpenAPI 3.1 document, signed webhooks, an MCP server for AI assistants and llms.txt.
Learn more about API and MCP -
Secure hosting
HIPAA-ready placement you turn on per database, under a signed BAA, with dedicated nodes and per-org keys.
Learn more about Secure hosting
Start today
Create your first database
A free instance, no card. Upgrade when you outgrow it; nothing converts silently.