Team and roles
Roles are per organisation. The same person can own one organisation and be a billing contact on another.
Roles
| Role | Can do |
|---|---|
| Owner | Everything, including creating and destroying instances |
| Admin | Manage instances and invite people; cannot remove an owner |
| Member | View instances and their status |
| Billing | See invoices and usage; no access to instances |
Someone who approves invoices does not need to see incident data, and giving them access anyway widens who can read production information for no reason.
Inviting someone
Owners and admins can invite from Team. The invitation link is valid for seven days and can only be used once. Inviting the same address again replaces the outstanding link rather than leaving two valid ones.
Accepting an invitation marks the address as confirmed — opening the link already proved control of it, so there is no second confirmation step.
A Thalamus AI Cloud account is not an instance account
These are separate identity systems, deliberately:
- Your Thalamus AI Cloud account manages subscriptions, instances and team membership.
- Your instance account is inside the running product and sees incident data.
Inviting someone to your organisation does not give them access to your instance. That is granted inside the instance itself.
Support access
Our support staff cannot see inside your instance by default. When access is needed, a grant is created that records who, why, and for how long. Grants:
- expire automatically, and never last more than 24 hours
- require a written reason
- log every use, not just that access was possible
- can be revoked by you at any time
You can see the full history — including whether you approved it — under your instance in the console. There is no shared support password.