Skip to main content
FeaturesTeams & Access
Teams & access

Multi-org. Multi-IdP. Per-tenant on every query.

Tenant ID is carried on the JWT and applied to every query as a row-level filter — there is no application-level 'pick a tenant' selector to misconfigure.

Multi-IdP
SAML + OIDC + social
SCIM 2.0
User lifecycle
Org-wide
Enforce-MFA available
Per-query
Tenant scoping

Multi-organisation membership

Belong to multiple orgs, switch with one click, and never accidentally make a change in the wrong one — every query carries the tenant ID.

  • Belong to unlimited organisations
  • Org switcher in the global header
  • Per-org JWT — switching reissues a fresh token
  • No application-level tenant selector to misconfigure
  • Tenant ID enforced at the query layer, not the application layer

Role-based access control

Owner, admin, member — assignable per-org. The boundary on every action is the role check at the handler, not a UI hide.

  • Owner — full control, billing, can transfer ownership
  • Admin — manage services, schedules, integrations, members
  • Member — operate services, acknowledge incidents
  • Per-role permission matrix surfaced in the settings UI
  • Authorization enforced at the handler layer
  • Custom RBAC roles (Enterprise)Roadmap

API keys

Per-key scope (read or write), per-key rate limits, per-key audit trail. Revoke with one click; rotation never requires a redeploy.

  • Per-key scope — read-only or read/write
  • Per-key creation actor and timestamp
  • Per-key last-used surfaced in the dashboard
  • One-click revocation
  • Per-key rate-limit overrides

Single sign-on (SAML + OIDC)

Per-org IdP configuration for SAML 2.0 (crewjam/saml) and OIDC. Just-in-time provisioning supported on both.

  • SAML 2.0 — per-org IdP metadata upload
  • OIDC — per-org client config (issuer, client ID, secret)
  • Just-in-time user provisioning
  • Group claim → role mapping
  • Per-org enforce-SSO toggle (Pro+)
  • Requires `SAML_SP_CERT_PEM` + `SAML_SP_KEY_PEM` env to enable SAML

SCIM 2.0 lifecycle

Enterprise plan only. User create / update / disable flows through your IdP — offboarding is one click in Okta.

  • Provision users from Okta, Azure AD, Google Workspace
  • Group membership → role mapping
  • Disable in IdP → revoke in AlertifyPro automatically
  • Per-org SCIM token with scoped permissions
  • Enterprise plan

TOTP MFA + org-wide enforcement

TOTP via any authenticator app, backup codes, and an org-wide enforce-MFA switch on Pro+ for compliance-driven teams.

  • TOTP setup with QR provisioning
  • Eight backup codes generated per setup
  • Per-user reset flow with admin override
  • Org-wide enforce-MFA (Pro+) — blocks login without MFA
  • MFA reset audit-logged

Social login

Google, GitHub and Microsoft. Linked-identity flow lets one user attach multiple providers.

  • Google, GitHub, Microsoft
  • Linked identities — one user, multiple providers
  • Provider-claim → role mapping
  • Disable per-org from settings

Service groups & team ownership

Group services by team, route alerts to the group, report per-group SLA. Mirrors how on-call actually works.

  • Per-group service ownership
  • Per-group on-call routing
  • Per-group SLA reporting
  • Hierarchical groups for large orgs
Teams & Access vs the market

How we stack up on teams & access

Only rows relevant to this capability. See the full comparison →

FeatureAlertifyProDatadogUptimeRobotPingdom
Multi-organisation membership
SAML 2.0 + OIDC SSO
SCIM 2.0 user lifecycle
TOTP MFA with org-wide enforcement
Per-key API key scopes
Audit log of access events

Frequently asked

Ready to see teams & access on your stack?

Spin up your first monitor in under a minute. Free forever for the first 5 services.