Teams
Create teams, manage members, and control access to your projects.
Teams
Teams are the organizational unit in KeyEnv. Every project belongs to a team, and team membership determines who can access your secrets. When you sign up, a personal team is created automatically.
Team Lifecycle
Creating a Team
- Click your team name in the sidebar
- Click Create Team
- Enter a team name (up to 100 characters)
- Click Create
The creator automatically becomes the team's first admin. New teams start on the Free plan.
Viewing Team Details
Navigate to Team in the sidebar to see:
- Team name and plan
- All current members with their roles
- Pending invitations
Renaming a Team
Team admins can rename a team from the team settings page. Click the edit icon next to the team name, enter the new name, and save.
Deleting a Team
Team deletion is handled by system administrators. If you need to delete a team, contact support. Deleting a team permanently removes all projects, secrets, and member associations.
Team deletion cannot be undone. Make sure to export any secrets you need before requesting deletion.
Team Roles
KeyEnv has two team-level roles: admin and member.
| Capability | Admin | Member |
|---|---|---|
| View team members and invitations | Yes | Yes |
| Access all environments (bypasses env permissions) | Yes | No |
| Invite and remove members | Yes | No |
| Change member roles | Yes | No |
| Create and delete projects | Yes | No |
| Manage billing and plan | Yes | No |
| Set default permissions | Yes | No |
| View audit logs | Yes | No |
| View and edit secrets | Yes | Per-environment |
| Manage environment permissions | Yes | Only if granted admin on that environment |
Team admins automatically have full access to all environments in every project. Regular members get access based on their per-environment permissions. See Environment Permissions for details.
Changing a Member's Role
- Go to Team in the sidebar
- Find the member in the list
- Click the role dropdown next to their name
- Select the new role
You cannot demote the last admin. Every team must have at least one admin at all times.
Inviting Members
Only team admins can invite new members.
Sending an Invitation
- Go to Team in the sidebar
- Click Invite Member
- Enter the invitee's email address
- Select a role (
adminormember) - Click Send Invite
The invitee receives an email with a link to join. If they do not have a KeyEnv account, they will be prompted to create one.
Members receive email notifications when invited to a team, when their role changes, and when they are removed from a team.
Invitation Expiration
Invitations expire after 30 days. If an invitation expires:
- The invitee can no longer accept it
- An admin must resend the invitation to generate a fresh link
Resending refreshes both the token and the expiration date.
Invitations and Member Limits
Pending invitations count toward your team's member limit. On the Free plan (1 member limit), you cannot send an invitation because the creator already fills the slot. Upgrade to Pro for unlimited members.
Managing Pending Invitations
Admins can view, resend, and revoke pending invitations:
- View: Go to the Invitations tab on the team page
- Resend: Click the resend button next to the invitation
- Revoke: Click the revoke button to cancel a pending invitation
Removing Members
Team admins can remove any member from the team:
- Go to Team in the sidebar
- Find the member in the list
- Click the remove button
- Confirm the removal
Non-admin members can only remove themselves (leave the team). They cannot remove other members.
Removed members immediately lose access to all project secrets. Their environment-level permissions are cleaned up automatically.
You cannot remove the last admin from a team. The sole admin must promote another member to admin before leaving.
Team Roles and Environment Permissions
KeyEnv uses a two-tier permission model:
- Team role (
adminormember) -- controls team-level operations - Environment permission (
none,read,write, oradmin) -- controls per-environment secret access
How they interact:
- Team admins bypass environment permissions entirely. They have full
adminaccess to every environment in every project. - Team members rely on their per-environment permissions. If a member has no permission set for an environment, they have
none(no access).
Default Permissions
Only team admins can configure default permissions for each environment. When a new member joins the team, they automatically receive these defaults. For example, you might set:
development->write(all new members can edit dev secrets)staging->read(all new members can view staging)production->none(no production access by default)
See Environment Permissions for full details on managing per-environment access.
Plan Limits
Team capabilities depend on your plan:
| Resource | Free | Pro | Enterprise |
|---|---|---|---|
| Team members | 1 | Unlimited | Unlimited |
| Projects | 3 | Unlimited | Unlimited |
| Secrets per environment | 100 | Unlimited | Unlimited |
| Environments per project | 3 | Unlimited | Unlimited |
When you reach a limit, you can still use existing resources but cannot create new ones. Upgrade to Pro to remove all limits.
See Billing for details on upgrading and managing your plan.
Audit Trail
All team actions are logged:
- Team created
- Member invited, accepted, removed
- Role changes
- Invitation sent, resent, or revoked
Access the audit log from the team settings page. Only team admins can view audit logs.
Best Practices
- Keep multiple admins -- If your sole admin loses access, no one can manage the team. Always have at least two admins for critical teams.
- Review access regularly -- Remove members who no longer need access. Check pending invitations and revoke stale ones.
- Use service tokens for CI/CD -- Do not share personal credentials with automated systems. Create scoped service tokens instead.
- Set default permissions thoughtfully -- Configure project defaults so new members get appropriate access without manual setup.
- Restrict production access -- Give most members
readornonefor production and reservewrite/adminfor senior engineers and DevOps.