Business & Enterprise Feature

Deploy together, stay in control

Invite your team, assign granular roles, restrict access per project, and track every action in a 1-year audit log. No more shared SSH keys.

Team management, built in

Everything you need to collaborate securely -- without bolting on third-party IAM tools.

Unlimited team members
Add as many collaborators as your project needs
4 granular roles
Owner, Admin, Developer, and Viewer
Per-project permissions
Control who can access which stacks and apps
Invite via email
Send invitations directly from the dashboard
1-year audit log
Full history of every action on the platform
Session management
View and revoke active sessions per user

How it works

01

Invite team members by email

Enter an email address in the dashboard and send an invitation. They create an account (or sign in) and land in your team automatically.

02

Assign roles

Choose from 4 roles: Owner (full control), Admin (manage team and apps), Developer (deploy and configure), or Viewer (read-only access).

03

Set per-project permissions

Restrict access at the stack or app level. A developer can have full access to staging but read-only on production.

04

Track everything in the audit log

Every deployment, configuration change, and access event is logged with timestamp, user, and action. Retained for 1 year.

The access control pipeline

Team Owner
Invite Members
Assign Roles
Per-Project Access
Audit Log
Compliance

From invitation to audit trail -- every step is tracked and enforced

Everything you need

4 granular roles

Owner, Admin, Developer, Viewer -- each with clearly defined permissions. No ambiguity about who can do what.

Per-project permissions

Assign roles per stack or per app. Give a contractor access to one project without exposing everything else on the server.

Email invitations

Invite team members by email. They receive a link, create an account, and are automatically added to your team with the assigned role.

1-year audit trail

Every action -- deployments, config changes, team modifications, login events -- is logged with who, what, and when. Exportable for compliance.

Session management

See all active sessions for every team member. Revoke any session instantly. Know exactly who is logged in and from where.

Two-factor authentication

Enforce 2FA for all team members. TOTP-based (Google Authenticator, Authy). Protect your infrastructure even if a password is compromised.

The old way

  • x Share SSH keys across the team
  • x One root account for everyone
  • x No visibility into who did what
  • x Manual access revocation
  • x No role separation
  • x Hope nobody breaks production

The sh0 way

  • Invite by email, no SSH keys needed
  • 4 roles with clear boundaries
  • Per-project access control
  • Full audit log for every action
  • Instant access revocation
  • 2FA for all accounts

Questions & answers

What roles are available? +
Four roles: Owner (full platform control, billing, team management), Admin (manage apps, team members, and settings), Developer (deploy, configure apps, view logs), and Viewer (read-only access to dashboards and logs).
Can I restrict access per project? +
Yes. Permissions are set at the stack or app level. You can give a developer full access to your staging stack while restricting them to viewer-only on production.
How does the audit log work? +
Every action on the platform is recorded with a timestamp, the user who performed it, and what changed. Logs are retained for 1 year and can be filtered by user, action type, or date range.
Can I enforce 2FA for my team? +
Yes. As an Owner or Admin, you can require two-factor authentication for all team members. Members who haven't enabled 2FA will be prompted to set it up on their next login.
How many team members can I add? +
There is no limit on team members. The Business plan and Enterprise plan both support unlimited collaborators at no additional per-seat cost.
Can I transfer ownership? +
Yes. The current Owner can transfer ownership to any Admin on the team. The transfer requires confirmation from both parties for security.

Collaborate without compromise

Granular roles, per-project permissions, and a full audit trail. Team management that actually works.