Teams, Workspaces, and RBAC
Overview
TokenTimer supports organizations through Workspaces and role-based access control (RBAC). Workspaces isolate tokens, alert preferences, and audit events. RBAC defines who can manage or view them.
Your organization is everything owned by one billing account: the owner, all their workspaces, and all members across those workspaces. Plans and member caps apply at the organization level.
Roles and Permissions
- Admin: full control; create/rename/delete workspaces and tokens, manage members, update preferences, view audit (org + workspace), manage billing.
- Workspace Manager: manage members (except admins), create/update/delete tokens, and update preferences within assigned workspaces; view workspace audit.
- Viewer: view tokens in assigned workspaces.
Practical guidance: grant Viewer to most teammates or auditors, Manager to service owners who renew assets, and Admin to a minimal set of billing/security owners.
Plan limits
Member, workspace, and delivery caps are per plan. The canonical numbers are in Plan limits; plan selection and prices are on the Pricing page.
Reaching a limit blocks new creations (for example tokens or invitations) until you move to a larger plan or clean up.
Pending invitations
When you invite a teammate who does not yet have a TokenTimer account, we create a pending invitation. The invitation stays pending until the invitee signs up and accepts, or an admin cancels it from the workspace settings.
How pending invitations count against the member limit
Your plan caps the number of members per organization. The invite check uses the formula:
active_members + pending_invitations + 1 <= plan_member_limit
A Pro organization with 8 active members and 3 pending invitations is already at 11 and will block the next invite even though only 8 people are actually using the product. See Plan limits for the member caps.
Cancelling an invitation
On the Workspaces page, under the members table, any admin or workspace manager can see the list of pending invitations and click "Cancel invite" to free up a slot.
Invitations clear automatically when the invitee accepts them. If you do not see an expected pending invitation, it has likely already been accepted or cancelled.
Practical guidance: Workspaces vs Sections
Choose the right boundary to keep ownership, billing, and notifications clean and predictable.
- Create a new workspace when you need:
- Isolated workspaces and notifications (e.g. different default contact points).
- Separate audit and membership boundaries (e.g. different customers).
- Create a new section when you need:
- Separate tokens by teams, products, or environments inside the same workspace.
- Different contact groups per section.
Transferring tokens between workspaces
Move tokens from one workspace to another without re-creating them. This keeps alert settings and history attributed to the correct workspace going forward.
- Where: open Workspaces, pick a workspace, then click Transfer tokens.
- Who: Admins; Workspace Managers may transfer if they are attributed to two or more workspaces.
- Plans: Pro and Team.
How To
- In the Workspace section, click on "Transfer tokens", select the source and destination workspaces.
- Use the search, category, or section filters to narrow the list.
- Select individual tokens or select all filtered tokens, then click Transfer selected.
Deleting a Workspace
Deleting a workspace removes its tokens, members, sections, invitations, and settings. Audit and delivery logs remain for history, with their workspace unlinked.
- Consider transferring tokens to another workspace beforehand if you still need alerts.
- Export data for an offline record.
This action is irreversible. Consider exporting data before deletion.
Alert Preferences are Workspace-scoped
Default thresholds and channels are configured per workspace. Recipients are managed via contact groups; a token uses its selected group, falling back to the workspace's default group. Groups can optionally define their own thresholds policy which overrides workspace defaults for assigned tokens.
- Use sections to route ownership (e.g., different teams) and filter dashboards.
- Changes to workspace thresholds apply to tokens without a group thresholds override.