Team and roles
Under Administration → Team, owners invite further administrators and decide what each may do. The administrator created by the setup wizard is an owner.
The four roles
Section titled “The four roles”| Role | May |
|---|---|
| Owner | Everything, including the team, the license, the installation settings and deleting a tenant. |
| Administrator | Set up and run tenants, sources, storage, schedules, integrations and legal holds. Not the team, the license or the installation settings. |
| Technician | Run backups, checks and restores, and open backed-up and archived content. Changes no configuration. |
| Read only | See status, reports and the audit log. No backed-up or archived content, no changes. |
The rules are enforced by the server for every request, not only by what the interface shows. A request a role does not cover is refused with “Your role in the provider team does not allow this.”
Tenants (Service Provider)
Section titled “Tenants (Service Provider)”Each member other than an owner has either all tenants, including tenants created later, or selected tenants. A member limited to selected tenants sees only those in the tenant list and the tenant switcher; other tenants answer as if they did not exist. Such a member cannot use views that span every tenant, such as the provider-wide statistics, the installation audit log or the team itself. Owners always have every tenant.
Inviting a member
Section titled “Inviting a member”- Administration → Team → Invite member: email address, name, role and, with Service Provider, the tenants.
- The person receives a single-use link, valid for 72 hours, to choose a password. With a mail transport configured (Settings → Mail) the link is emailed; otherwise it is shown once for you to hand over.
- After choosing the password they set up an authenticator app, as every password sign-in in Restow requires; a passkey can be added afterwards.
An address that already belongs to an account cannot be invited, so an account of a customer’s own tenant never turns into an administrator of the installation unnoticed. An invitation that expired can be renewed with New invitation link.
Changing and removing
Section titled “Changing and removing”- Change role takes effect with the member’s next request; no sign-out is needed.
- Remove ends the member’s sessions at once and invalidates an open invitation. An account that belongs to no tenant is deleted.
- The team always keeps at least one owner: the last owner can neither be given another role nor be removed. Make someone else an owner first.
Every invitation, change and removal is written to the installation’s audit log.