Team Management

Organization Overview

The Team page manages membership and access control. Info cards show Total Members, Administrators, and Pending Invites. Multi-org users see an Organization Switcher dropdown.

Members Table

Email, Role (Administrator/Member), Join Date, and admin-only actions. Administrators can change an existing member's role inline with Make admin / Make member, or remove them. Promoting a member to admin grants full organization management — including org-level security controls such as the behavioral-detection allowlist (the change takes effect once the member's session token refreshes).

Roles & Permissions

CapabilityAdministratorMember
View agents, health, sessions, alerts
Configure agents
Run live sessions and queries
Invite/remove members
Create/revoke registration tokens
Purchase subscriptions for members
Manage org settings & billing
Delete organization (creator only)✓*

* Only the user who originally created the organization can delete it, even if other users have the Administrator role.

Inviting Members

  1. Click Invite Member (admin only)
  2. Enter email and select the Clerk role (Administrator or Member)
  3. Optionally tick any roles this invitation carries — they are applied automatically when the person accepts, so a new technician can work on day one instead of waiting for a second grant
  4. Choose whether those roles apply to this organization only or to every organization in the workspace
  5. Click Send Invite
  6. Invitation appears in Pending Invitations table with Revoke option

Shared Resources: All org members share the same query pool, agents, alert rules, notification channels, and agent seats.

Workspace cascade: When a new member accepts an invitation that lands them in your workspace, they are automatically added to every Clerk organization in the workspace, not just the one they were invited into. Likewise, if you create a new organization later, all existing workspace members are added to it. This means “workspace member” and “has access to all orgs in the workspace” are equivalent. To grant org-only access (e.g. a client contact who should see only their own organization), invite them at the organization's URL rather than at your workspace URL.

Roles & Privileges

Two separate systems decide what someone can do. The Clerk role (Member or Administrator) comes with the invitation. Privileges are granted per person from Team → Workspace → Roles & privileges, or attached to an invitation so they apply on acceptance.

Clerk roles

RoleWhat it means
MemberThe default for a new invitation. Can read everything in the organization — agents, health, events, alerts, reports, patch status — and act on their own things: their own saved views, time entries, AI analyses and notification subscriptions. Cannot delete or deactivate anything shared.
AdministratorEverything a Member can do, plus organization configuration: alert rules and channels, automations, AI settings, gateways, and inviting or removing members. Counts as a workspace owner for every purpose except granting privileges. Also carries the Technician privilege automatically.
OwnerThe person who created the organization or workspace. Everything an Administrator can do, plus granting and revoking the privileges below.

Why administrators cannot grant privileges: any administrator can promote any member to administrator. If administrators could also hand out privileges, one administrator could create more administrators and, through them, distribute every privilege in this list — including the two below that deliberately withhold themselves from administrators. Granting stays with an owner so that chain has a person in it.

Privileges

PrivilegeWhat the holder can doIncluded with Administrator?
TechnicianManage agents and the things that drive them: deactivate and uninstall agents, reset agent configuration, apply a monitoring preset to many agents at once, and manage tags, scripts, script repositories, patch policies, maintenance-window overrides and file transfers. This is the level between Member and Administrator — day-to-day endpoint work without organization configuration.Yes
Session managerReview and end other members' active remote desktop, live query and shell sessions from the Team page.Yes
Timesheet approverApprove and reject timesheets, classify billable time, manage member rates, and read other members' time data.No
Billing approverGenerate draft Stripe invoices from approved billable time.No — deliberately. Approving time and turning it into an invoice are separate acts.
Detection editorAuthor changes to behavioural detection policy, custom rules, tuning and allowlists. Authoring is not applying: a change that weakens security waits for a Detection approver.No
Detection approverApprove or reject pending security-weakening detection changes proposed by someone else. Holding both this and Detection editor still does not let you approve your own proposal.No — deliberately. The value of this privilege is that its holder is not the proposer.
Additional ownerEverything an owner can do, including granting and revoking every privilege here. Cannot be attached to an invitation — invite the person first, then grant it.No

Scope

Every privilege is granted either to this organization only or to every organization in the workspace. A workspace-scoped grant covers organizations created later too, which is usually what an MSP wants: grant a technician once rather than repeating it for each client organization.

Removing access: privileges are revoked from the same Roles & privileges panel. Changing someone from Administrator to Member in Clerk takes effect immediately — there is nothing to sync, and they lose owner and technician rights on their next action. Any privilege granted to them explicitly survives that change and must be revoked separately.

Team Subscriptions

Organization admins can purchase query subscriptions on behalf of team members. This ensures every member has access to AI diagnostics without requiring each person to manage their own billing.

How It Works

  1. From the Dashboard, click Manage Team Subscriptions in Quick Actions
  2. A modal displays all organization members with their current subscription status
  3. For any unsubscribed member, click Buy Plan
  4. Select a tier (Professional, Business, or Enterprise) and click Proceed to Checkout
  5. Complete payment in Stripe — the subscription is created immediately for the target member

Subscription Ownership

  • Admin-purchased: The admin who bought the subscription can cancel it. The subscription's billing is tied to the organization's Stripe customer. Shown with an “Admin-purchased” badge.
  • Self-purchased: Members who buy their own subscription manage it through their personal Stripe billing portal. Shown with a “Self” badge. Admins cannot cancel self-purchased subscriptions.

Cancelling Admin-Purchased Subscriptions

Click the Cancel button next to any admin-purchased subscription. Cancellation takes effect immediately with prorated billing.

How Subscriptions Pool

Each subscribed member contributes their tier's query quota and 20 free agent seats to the organization pool. For example, if an admin purchases Professional for 3 members, the org gets 3,000 queries/month and 60 free agent seats.

Creating Organizations

Organizations are the fundamental scoping boundary in ET Ducky. Every resource — agents, registration tokens, alert rules, notification channels, queries, tags, and team members — belongs to exactly one organization.

When to Create Separate Organizations

  • MSP / Multi-Client: Create one organization per client to keep agents, billing, and data fully isolated
  • Environment Separation: Separate Production, Staging, and Development environments into distinct orgs for access control
  • Business Units: Large enterprises can use orgs to give each team independent query pools and agent budgets

How to Create

  1. Click + New Organization on the Dashboard, Team page, or Agent Setup page
  2. Enter an organization name
  3. Click Create Organization — the new org is created via Clerk and set as your active org immediately
  4. Invite team members and set up subscriptions as needed

Multi-Org Users: Use the organization dropdown on the Dashboard, Agents, and Team pages to switch between organizations. All metrics, agents, and settings update to reflect the selected org.

Subdomain ↔ Org Name

If your workspace uses a custom subdomain (e.g. acme.etducky.com), renaming the subdomain on the Workspaces & Custom Domains page cascades automatically to the underlying Clerk organization name. This keeps the org name in the switcher dropdown in sync with your subdomain — no more “why is my org called swift-otter-823 when my subdomain is acme?” mismatch. Members don’t need to refresh; the Clerk webhook propagates the rename within a few seconds.

Deleting Organizations

Only the original creator of an organization can delete it. Organization deletion is permanent and irreversible.

What Gets Deleted

  • All agents registered to the organization
  • All registration tokens
  • All alert rules and notification channels
  • All query history and usage data
  • All team memberships and pending invitations
  • All associated billing subscriptions

How to Delete

  1. Navigate to the Team page
  2. Select the organization you want to delete from the dropdown (if you have multiple)
  3. Click the red Delete Organization button in the Organization info card (visible to admins only)
  4. Type the organization name exactly as shown to confirm
  5. Click Delete Organization to proceed

Creator-Only: If you are an admin but not the creator of the organization, the deletion will be rejected by the server. Only the user who originally created the organization can delete it.

Registration Tokens

Registration tokens are the secure method for authenticating agent installations. Only organization admins can create and manage tokens.

Creating Tokens

  1. Navigate to the Agent Setup page
  2. Click + New Token
  3. Give it a descriptive name (e.g., “Production Servers”, “IT Team Deploy”)
  4. Optionally set a max agent limit and expiry date
  5. After creating the token, the page shows ready-to-run Windows and Linux install instructions for that token
  6. Click Download to get the standard signed agent installer, then run it with this token on the command line (the Windows and Linux commands are shown on the page)

Deployment: The Download button provides the standard signed installer; supply the token on the command line (or paste it into the installer wizard when run interactively). The same installer works for every token, on Windows or Linux. There is no limit on the number of registration tokens an organization can create.

Token Security

  • Tokens are stored as SHA-256 hashes — the plaintext is never persisted
  • An encrypted copy of the token is stored server-side to enable on-demand installer downloads
  • Each token is scoped to a single organization
  • Tokens can be revoked at any time to prevent further registrations and disable installer downloads
  • Use separate tokens per environment (production, staging, dev) for audit control
  • Usage counters track how many agents each token has registered

Managing Tokens

The Agent Setup page lists all tokens for your organization with their prefix, name, usage count, status, and expiry. Use the Download button to get the standard signed installer (run it with the token), Revoke to disable a token, or Delete to remove it permanently.