Roles & permissions

Updated April 15, 2026

Control who can do what across your Hyperping account and projects. Four roles give you fine-grained control, with every resource scoped inside a project, and team members only seeing the projects they belong to.

The Members page with the role dropdown showing Owner, Admin, and Billing descriptions
Assign roles from the Members page; each member's role applies per project

At a glance

Model
Role-based access control
Roles
Owner, Admin, Member, Billing
Scope
One role per project
Default
Member

The four roles

One Owner per account. All other team members are assigned one of three roles: Admin, Member, or Billing.

Owner
Unrestricted

The Owner has full access to the entire account. Exactly one Owner per account.

Usually assigned to the founder or account holder. Transferring ownership changes the previous Owner to Member.

Admin
Manages people + config

Same capabilities as the Owner except billing and ownership transfer.

Usually assigned to a team lead or manager who maintains the monitoring configuration.

Member
Default role

Can manage monitors and respond to incidents within their assigned project.

Usually assigned to an engineer who configures monitors and responds to incidents.

Billing
Read + billing

Read-only access to project data plus the ability to manage subscription and payment details.

Usually assigned to a finance or operations contact who handles invoices and plan changes.

Permission matrix

Quick reference for every capability. A check means allowed, and a minus sign means blocked.

ActionOwnerAdminMemberBilling
Read access
View monitors, reports, and outages
View on-call schedules
View teammates list
Monitoring and incidents
Create, edit, and delete monitors-
Bulk-edit monitors-
Create and update on-call schedules-
Delete on-call schedules--
Create outages-
Acknowledge and resolve outages-
Escalate outages-
Update outage severity and details-
Write postmortems and AI summaries-
Delete outages-
Account administration
Invite and remove teammates--
Transfer account ownership---
Manage billing and subscription--
Configure SSO and authentication---

Project isolation

Projects act as boundaries. A teammate invited to Project A cannot see monitors, status pages, or integrations in Project B. Only the Owner sees every project.

acme.com
Project A

Production monitors, public status page, and on-call rotation.

Jane is Owner, Marcus is Admin, and Priya is Member.

staging.acme.com
Project B

Staging monitors and internal incident workflows.

Jane is Owner, Ren is Admin, and Sasha is Member. Priya has no access.

Common ways to split work across projects:

  • Create one project per client when teams should not see each other's monitors.
  • Separate engineering, infrastructure, and support when each team owns different services.
  • Keep production and staging apart when access or alerting differs by environment.

Pick a role

Common mappings from job title to recommended role:

Team memberResponsibilityRole
CTO or team leadManages the team and configurationAdmin
EngineerSets up monitors and responds to incidentsMember
Finance or operationsHandles invoices and plan changesBilling

Account security

Two-factor authentication
Authentication

Add a second verification step to login. Once enabled, you need your password plus a code from your authenticator app.

Enable it in your account settings. It is available on every plan.

Audit logs
Traceability

Hyperping records who changed a setting, when it changed, and which project it affected.

Use the log to review configuration changes after an incident or during a compliance audit.

Data protection
Storage

Data is encrypted at rest with LUKS and in transit with SSL/HTTPS.

Hyperping stores data in DigitalOcean's Frankfurt region and provides self-service data deletion.

Troubleshooting

A teammate says they can't see a project

Team members only see projects they were invited to. Check the Teammates page while inside the correct project to verify they were invited there.

A teammate needs to manage billing

Assign them the Billing role, or let the Owner handle it directly. Change roles on the Teammates page.

An SSO user can't log in

Check the provisioning policy in your SSO settings. If it's set to "Invite-only," the user needs to be invited before SSO login will work. See login methods for details.

Next steps