Deploy together, stay in control
Invite your team, assign granular roles, restrict access per project, and track every action in a 1-year audit log. No more shared SSH keys.
Team management, built in
Everything you need to collaborate securely -- without bolting on third-party IAM tools.
How it works
Invite team members by email
Enter an email address in the dashboard and send an invitation. They create an account (or sign in) and land in your team automatically.
Assign roles
Choose from 4 roles: Owner (full control), Admin (manage team and apps), Developer (deploy and configure), or Viewer (read-only access).
Set per-project permissions
Restrict access at the stack or app level. A developer can have full access to staging but read-only on production.
Track everything in the audit log
Every deployment, configuration change, and access event is logged with timestamp, user, and action. Retained for 1 year.
The access control pipeline
From invitation to audit trail -- every step is tracked and enforced
Everything you need
4 granular roles
Owner, Admin, Developer, Viewer -- each with clearly defined permissions. No ambiguity about who can do what.
Per-project permissions
Assign roles per stack or per app. Give a contractor access to one project without exposing everything else on the server.
Email invitations
Invite team members by email. They receive a link, create an account, and are automatically added to your team with the assigned role.
1-year audit trail
Every action -- deployments, config changes, team modifications, login events -- is logged with who, what, and when. Exportable for compliance.
Session management
See all active sessions for every team member. Revoke any session instantly. Know exactly who is logged in and from where.
Two-factor authentication
Enforce 2FA for all team members. TOTP-based (Google Authenticator, Authy). Protect your infrastructure even if a password is compromised.
The old way
- x Share SSH keys across the team
- x One root account for everyone
- x No visibility into who did what
- x Manual access revocation
- x No role separation
- x Hope nobody breaks production
The sh0 way
- Invite by email, no SSH keys needed
- 4 roles with clear boundaries
- Per-project access control
- Full audit log for every action
- Instant access revocation
- 2FA for all accounts
Questions & answers
What roles are available? +
Can I restrict access per project? +
How does the audit log work? +
Can I enforce 2FA for my team? +
How many team members can I add? +
Can I transfer ownership? +
Collaborate without compromise
Granular roles, per-project permissions, and a full audit trail. Team management that actually works.