Team seats: bring your whole team

Until now a PlainDMARC account was one login. Now you can invite your whole team — a colleague who should see everything and change things, or a client who should just watch the verdicts land. Three roles, seats that scale with your plan, and nothing to configure.

Three roles

Every member is one of three things:

  • Full access (owner) — everything you can do today: add and remove domains, edit branding, manage billing and API keys, invite and remove other members.
  • Admin — runs the team and branding day to day: invites and removes view-only members and edits the white-label branding, and sees every domain and verdict. An admin can't touch billing, API keys, or account settings, and can't create other owners or admins — that stays with the owner.
  • View-only — reads every domain, every weekly verdict, and the sender breakdowns, but changes nothing. Any attempt to write is refused with a plain read-only message. It's the same guarantee a read-only API key gives — visibility without control.

That's the whole model in v1: three clear roles, easy to reason about. It's the safe way to hand a client a window into their own email health, give a junior teammate the full picture without the ability to break anything, or let a manager run the team without handing over billing.

Seats scale with your plan

Each plan includes a set number of seats — the member and any pending invites both count against it:

PlanTeam seats
Free1 (just you)
Solo2
Agency5
Agency+10

See it on the pricing page, where every plan card shows its seat count next to the domain cap.

Inviting someone takes about a minute

  1. Open the Team screen in your dashboard.
  2. Enter a teammate's email, pick a role — view-only, admin, or full access — and send the invite.
  3. They open the link, sign in as that email — which is how PlainDMARC knows it's really them — and they're in.

You can change a member's role — promote a view-only member to admin or full access, or step them back down — at any time. An account always keeps at least one full-access owner, so you can't accidentally lock yourselves out.

Downgrades pause, they never delete

If you move to a smaller plan and end up with more members than seats, the extra members are paused — not removed. They keep their place and simply can't act until seats free up; the next upgrade brings them back, owners first. It's the same rule we already use for domains: PlainDMARC never quietly deletes your data because a plan changed.

Invite a client, scoped to their own domain

On the Agency plans you can also invite a client — a view-only login scoped to only the specific domains you pick. They sign in and see their own domain's verdicts and reports, and nothing else: not your other clients, not your team, not your settings. Client logins are a separate allowance from team seats, so giving each client access doesn't eat into your staff seats.

What's not here yet — plainly

We'd rather tell you the edges than let you find them:

  • Three fixed roles, not a custom permission matrix. Owner, admin, and view-only cover the common cases; you can't yet define your own per-feature permission sets.
  • No SSO or SCIM. Members sign in with the same email magic-link everyone uses.

These are on the list. What shipped is the part most teams actually needed first: a second (and third, and tenth) safe pair of eyes — and a way to give each client a window into just their own email health.

Invite your team. Team seats are included on every plan — the Free plan needs no card.

See plans & seats → Start free DMARC monitoring