9. Users, workspaces and security
Workspaces
A workspace holds projects, integrations (Google, DataForSEO), AI tokens and members. Agencies typically use one workspace per client team; everyone else needs only one. If you belong to several workspaces, switch between them at the top of the sidebar.
The number of workspaces depends on your edition: Starter 1, Pro 3, Agency unlimited.
Roles
| Role | Can |
|---|---|
| Owner | Everything in the workspace, including deleting it |
| Admin | Everything except deleting the workspace: projects, integrations, members, AI tokens, audit log |
| Member | View and edit projects, start paid analyses (metrics, rank checks) |
| Viewer | View projects only |
Projects can additionally be limited to certain members. A foreign project is simply not found.
The installation administrator (created by the installer) also manages the installation itself under System: health, jobs, licence, backups, updates and the Google app.
Team members
Workspace → Members lists who has access to the workspace and with which role. Owners and admins also manage members there.
Adding a member
Under Add a member, enter the person's e-mail address and choose a role (Admin, Member or Viewer).
- The address already has an account (for example a colleague in another workspace): the person is added right away.
- New person: you get an invitation link. Copy it and send it to them yourself, for example by e-mail or chat, because SEO Control Center does not send e-mails. On the link's page, they choose their name and password and can then sign in.
The link is shown only once, works once and expires after 7 days. Open invitations are listed under Open invitations. If a link is lost or went to the wrong person, revoke it and add the person again.
Changing roles and removing members
- Change a member's role in the table and click Save.
- Remove takes away the person's access to this workspace immediately. Their account remains, along with any other workspaces they belong to.
Some limits keep a workspace safe:
- the Owner role cannot be given here;
- only an owner can change or remove another owner;
- nobody can change their own role or remove themselves.
Every change is recorded in the Audit log.
Signing in securely
Under Account security:
- Two-factor sign-in: scan the QR code with an authenticator app and confirm with a code. Store the recovery codes somewhere safe; each one works once if you lose your phone.
- Sessions: Sign out other sessions ends every session except the current one, for example after using a shared computer.
Further protection:
- repeated wrong passwords are slowed down and limited;
- sessions end after a period of inactivity;
- every sensitive action is recorded in the Audit log.
Your data
- All SEO data stays in your own database on your server.
- Passwords are stored only as secure hashes. Google and DataForSEO credentials, and two-factor secrets, are stored encrypted.
- SEO Control Center contacts only these services:
- Google, for Search Console;
- DataForSEO, if connected;
- the license server, about once a week: licence key, installation ID, domain and version, never SEO data.