Team and roles

Roles are per organisation. The same person can own one organisation and be a billing contact on another.

Roles

RoleCan do
OwnerEverything, including creating and destroying instances
AdminManage instances and invite people; cannot remove an owner
MemberView instances and their status
BillingSee invoices and usage; no access to instances
Billing is deliberately not an instance role

Someone who approves invoices does not need to see incident data, and giving them access anyway widens who can read production information for no reason.

Inviting someone

Owners and admins can invite from Team. The invitation link is valid for seven days and can only be used once. Inviting the same address again replaces the outstanding link rather than leaving two valid ones.

Accepting an invitation marks the address as confirmed — opening the link already proved control of it, so there is no second confirmation step.

A Thalamus AI Cloud account is not an instance account

These are separate identity systems, deliberately:

Inviting someone to your organisation does not give them access to your instance. That is granted inside the instance itself.

Support access

Our support staff cannot see inside your instance by default. When access is needed, a grant is created that records who, why, and for how long. Grants:

You can see the full history — including whether you approved it — under your instance in the console. There is no shared support password.