Teams & Permissions

Give access without
giving away control

Your developer needs to deploy. Your client needs to see uptime. Neither needs your password. Organizations, teams and granular per-server permissions let you hand out exactly the access each person needs.

Permissions Matrix
Scoped
Server: prod-web-01App: storefront
SFTP / File access
Databases
Deploy
Delete

Section-level visibility — show SFTP, hide databases

3

Roles (admin, developer, read-only)

2

Access levels (per-server, per-app)

0

Shared credentials

1

Click to revoke

Access Control

Access scoped to exactly what each person needs

Your developer needs to deploy. Your client needs to see uptime. Neither needs your password. Organizations, teams, and granular per-server and per-application permissions let you hand out exactly the access each person needs.

Organizations

Top-level account that owns your servers, applications, and billing

Teams & Roles

Group members, scope access, assign admin/developer/read-only roles

Per-Server Permissions

Full or scoped access — control which panel sections a member sees

Per-App Permissions

Down to a single app — deploy to one without seeing the others

Sub-User Accounts

Restricted server-level accounts with their own credentials and SSH keys

Organization

Organizations — the top-level account

Your account is an organization — the top-level grouping that owns your servers, applications, and billing. Within it, you manage members, create teams, and decide who can reach what. Everything lives under one organization, but not everyone in it sees everything.

  • Organization is the top-level account that owns your infrastructure
  • Member management with invite and removal by email
  • Billing and ownership stay with the organization, not individuals
  • One organization can hold many teams and many servers

Acme Inc.

Organization · 4 members

Billing and ownership stay with the organization

Teams

Teams and roles — reusable groupings

Group members into teams and scope each team's access to specific servers and applications. A team is a reusable grouping — 'frontend devs', 'agency clients', 'on-call engineers' — with a shared access level. Roles within a team control what members can do: admin, developer, or read-only.

  • Create teams and assign members to them
  • Scope each team to specific servers and applications
  • Roles: admin, developer, read-only
  • Reassign a member between teams without recreating their login
Teams
Frontend Devs3 members
Developerscope: storefront
Agency Clients2 members
Read-onlyscope: marketing
On-Call4 members
Adminscope: prod-web-01

Reusable groupings — scope each team to specific servers and apps

Permissions

Per-server and per-application permissions

Control which panel sections a member sees. Grant SFTP without database access. Restrict who can deploy or delete. Permissions are scoped per server and per application, so a teammate can deploy to one app on a server without seeing the others — or you can grant full server access to a senior engineer.

  • Per-server access control — full or scoped
  • Per-application access control — down to a single app
  • Section-level visibility — show SFTP, hide databases, restrict deploy and delete
  • Grant SFTP without database access, or database access without deploy rights
Permissions Matrix
Scoped
Server: prod-web-01App: storefront
SFTP / File access
Databases
Deploy
Delete

Section-level visibility — show SFTP, hide databases

Sub-Users

Sub-user accounts with instant revocation

Restricted server-level accounts for teammates who need to log into a server but should not control it. A sub-user gets their own credentials and SSH keys for a specific server, without access to the panel's management functions. Revoke a sub-user and their server access ends immediately.

  • Restricted server-level accounts, separate from panel admin
  • Per-server credentials and SSH keys
  • No access to panel management functions — server access only
  • Revoke instantly when someone leaves
Sub-User Accounts
Server-only

deploy-bot

ssh-rsa AAAA••••

prod-web-01

ci-runner

ssh-ed25519 BBB••••

prod-web-02

temp-dev

ssh-rsa CCCC••••

staging-01Revoked

Revoke instantly — server access ends immediately

Audit Trail

Every action tied to a person

Because every teammate logs in as themselves, every deployment, configuration change, and SSH session is attributable to a person — not a shared account. The audit trail records who did what, so you can investigate after the fact rather than guessing which shared login made a change.

Every action tied to a named user, not a shared account

Audit trail for deployments, configuration changes, and SSH sessions

Revoke access instantly when someone leaves

Audit Log
Live

Deployed storefront

[email protected]

2m ago

Changed Nginx config

[email protected]

14m ago

SSH session ended

ci-runner

1h ago

Viewed uptime

[email protected]

3h ago
Keep building

Everything around your team

Pair team permissions with the tools that keep your applications fast, secure, and resilient.

FAQ

Frequently Asked Questions

Everything you need to know about this service.

Contact Support

Permissions can be scoped per server and per application, down to which panel sections a member sees. You can grant SFTP without database access, or restrict who can deploy or delete — each person sees only what they need.

Yes. SharkCluster supports organizations, teams, and per-server and per-app permissions, so each teammate gets their own login with access scoped to exactly what they need — no shared credentials.

An organization is the top-level account. Within it, you create teams and assign members, then scope each team's access to specific servers and applications. A team is a grouping of members with shared access.

Start your journey today

Ready to take control
of your hosting?

Deploy servers, run self-hosted business apps, and keep your data on your own VPS — with a dedicated DevOps manager by your side.

No lock-in contracts
No credit card required
Dedicated DevOps manager