Team seats: bring your whole team
Until now a PlainDMARC account was one login. Now you can invite your whole team — a colleague who should see everything and change things, or a client who should just watch the verdicts land. Three roles, seats that scale with your plan, and nothing to configure.
Three roles
Every member is one of three things:
- Full access (owner) — everything you can do today: add and remove domains, edit branding, manage billing and API keys, invite and remove other members.
- Admin — runs the team and branding day to day: invites and removes view-only members and edits the white-label branding, and sees every domain and verdict. An admin can't touch billing, API keys, or account settings, and can't create other owners or admins — that stays with the owner.
- View-only — reads every domain, every weekly verdict, and the sender breakdowns, but changes nothing. Any attempt to write is refused with a plain read-only message. It's the same guarantee a read-only API key gives — visibility without control.
That's the whole model in v1: three clear roles, easy to reason about. It's the safe way to hand a client a window into their own email health, give a junior teammate the full picture without the ability to break anything, or let a manager run the team without handing over billing.
Seats scale with your plan
Each plan includes a set number of seats — the member and any pending invites both count against it:
| Plan | Team seats |
|---|---|
| Free | 1 (just you) |
| Solo | 2 |
| Agency | 5 |
| Agency+ | 10 |
See it on the pricing page, where every plan card shows its seat count next to the domain cap.
Inviting someone takes about a minute
- Open the Team screen in your dashboard.
- Enter a teammate's email, pick a role — view-only, admin, or full access — and send the invite.
- They open the link, sign in as that email — which is how PlainDMARC knows it's really them — and they're in.
You can change a member's role — promote a view-only member to admin or full access, or step them back down — at any time. An account always keeps at least one full-access owner, so you can't accidentally lock yourselves out.
Downgrades pause, they never delete
If you move to a smaller plan and end up with more members than seats, the extra members are paused — not removed. They keep their place and simply can't act until seats free up; the next upgrade brings them back, owners first. It's the same rule we already use for domains: PlainDMARC never quietly deletes your data because a plan changed.
Invite a client, scoped to their own domain
On the Agency plans you can also invite a client — a view-only login scoped to only the specific domains you pick. They sign in and see their own domain's verdicts and reports, and nothing else: not your other clients, not your team, not your settings. Client logins are a separate allowance from team seats, so giving each client access doesn't eat into your staff seats.
What's not here yet — plainly
We'd rather tell you the edges than let you find them:
- Three fixed roles, not a custom permission matrix. Owner, admin, and view-only cover the common cases; you can't yet define your own per-feature permission sets.
- No SSO or SCIM. Members sign in with the same email magic-link everyone uses.
These are on the list. What shipped is the part most teams actually needed first: a second (and third, and tenth) safe pair of eyes — and a way to give each client a window into just their own email health.
Invite your team. Team seats are included on every plan — the Free plan needs no card.
See plans & seats → Start free DMARC monitoring