Team Management
PerfLeaf supports team logins, letting a primary account holder invite additional people to access the same sites, scans, and reports. Team members share the owner’s workspace, while billing and account management stay locked to the primary account holder.
How team accounts work
Section titled “How team accounts work”Every PerfLeaf account has a single primary account holder (the owner). When you invite a teammate, PerfLeaf creates a separate login for them that is linked back to your account via a parentUser relationship.
- All data the team member creates or views — sites, scans, reports, exports, annotations — is attributed to the primary account holder, not the team member.
- Team members sign in with their own email and password but land in the owner’s workspace.
- The primary account holder is the only person who can invite, remove, or reinstate team members.
This keeps a single source of truth for billing, plan limits, and data ownership while allowing multiple people to collaborate.
Plan requirements
Section titled “Plan requirements”Team logins are available on the Bloom plan, which includes up to 5 team member seats (in addition to the primary account holder).
- On Sprout and Grow, the Team page shows a banner explaining that team logins aren’t available, with a link to upgrade.
- Custom plans can have team logins enabled with a configurable seat limit set by PerfLeaf staff.
If you’ve used all your seats, the invite form is disabled until you remove a member or upgrade.
The Team page
Section titled “The Team page”The Team page (/dashboard/team) is where you manage team members. Only the primary account holder can access it — team members who try to visit are redirected to the dashboard.
The page shows:
- A seat counter (
X / Y seats used) so you can see your remaining capacity at a glance. - An invite form to add new team members.
- A team members list with each member’s name, email, the date they were added, and their current status.
Member statuses
Section titled “Member statuses”| Status | Meaning |
|---|---|
| Invite pending | The member hasn’t set their password yet. You can resend the invite. |
| Email unverified | The member has set a password but hasn’t verified their email address. |
| Removed | The member has been soft-disabled and can no longer log in. They can be reinstated. |
Inviting a team member
Section titled “Inviting a team member”- Go to Dashboard → Team.
- In the Invite a team member card, enter the teammate’s Name and Email.
- Click Send invite.
PerfLeaf will:
- Create a new user record linked to your account.
- Email the teammate an invitation with a secure, time-limited onboarding link (valid for 7 days).
- The teammate follows the link to the Set Password page, where they choose their own password and complete onboarding.
You can’t invite an email address that’s already registered as a PerfLeaf account, and you can’t invite yourself. If a previously-removed member’s email is reused, you’ll be prompted to use the Reinstate button instead.
Managing team members
Section titled “Managing team members”Removing a member
Section titled “Removing a member”Removing a team member soft-disables their account:
- They can no longer log in.
- Their record is kept so historical attribution is preserved.
- They can be reinstated later without losing their original login.
To remove a member, click the Remove (trash) button on their row in the team list.
Reinstating a removed member
Section titled “Reinstating a removed member”Removed members can be brought back at any time, as long as you have a free seat:
- Find the removed member in the list (they’ll be tagged Removed).
- Click the Reinstate (rotate) button.
They’ll be able to log in again with their existing credentials. If you’ve reached your seat limit, you’ll need to remove another member or upgrade first.
Resending an invite
Section titled “Resending an invite”If a pending member hasn’t completed onboarding — for example, the invite email went to spam or the link expired — you can resend it:
- Find the member with the Invite pending tag.
- Click the Resend Invite (send) button.
A new onboarding token is generated and a fresh email is sent. Resend is only available for members who haven’t yet set their password.
Permissions: owner vs team members
Section titled “Permissions: owner vs team members”The primary account holder and team members have different capabilities within the shared workspace.
Primary account holder (owner)
Section titled “Primary account holder (owner)”The owner can do everything, including:
- Invite, remove, reinstate, and resend invites to team members
- Add, edit, and remove sites
- Start and schedule scans
- View and export reports
- Manage the company profile
- Upgrade or change the plan and view invoices
- Schedule account deletion
- Manage integrations (GitHub, Google Analytics)
Team members
Section titled “Team members”Team members can collaborate on monitoring work but cannot change account or billing settings:
| Capability | Team member access |
|---|---|
| View sites, scans, and reports | Yes |
| Add and manage sites | Yes |
| Start and schedule scans | Yes |
| Create annotations and exports | Yes |
| Use AI features (suggestions, action plans, report chat) | Yes |
| Manage integrations | Yes |
| Invite or remove team members | No |
| Change plan or view invoices | No |
| Edit company profile | No |
| Schedule account deletion | No |
Team members also can’t see the owner’s billing history, OAuth tokens, or account-deletion scheduling — those fields are restricted to the owner and PerfLeaf admins.
Data and security notes
Section titled “Data and security notes”- Single workspace: All team members work within the owner’s workspace. There’s no per-member data isolation within a team.
- Login security: Removed members are blocked from logging in immediately via a server-side check, not just a UI toggle.
- Role protection: Team members can’t elevate themselves to admin or reassign themselves under a different owner — those fields are admin-only.
- Onboarding tokens: Invite links are single-use, time-limited (7 days), and rotated on each resend so stale links can’t be reused.