User guide: Users, workspaces and security

9. Users, workspaces and security

Workspaces

A workspace holds projects, integrations (Google, DataForSEO), AI tokens and members. Agencies typically use one workspace per client team; everyone else needs only one. If you belong to several workspaces, switch between them at the top of the sidebar.

The number of workspaces depends on your edition: Starter 1, Pro 3, Agency unlimited.

Roles

RoleCan
OwnerEverything in the workspace, including deleting it
AdminEverything except deleting the workspace: projects, integrations, members, AI tokens, audit log
MemberView and edit projects, start paid analyses (metrics, rank checks)
ViewerView projects only

Projects can additionally be limited to certain members. A foreign project is simply not found.

The installation administrator (created by the installer) also manages the installation itself under System: health, jobs, licence, backups, updates and the Google app.

Team members

Workspace → Members lists who has access to the workspace and with which role. Owners and admins also manage members there.

Adding a member

Under Add a member, enter the person's e-mail address and choose a role (Admin, Member or Viewer).

  • The address already has an account (for example a colleague in another workspace): the person is added right away.
  • New person: you get an invitation link. Copy it and send it to them yourself, for example by e-mail or chat, because SEO Control Center does not send e-mails. On the link's page, they choose their name and password and can then sign in.

The link is shown only once, works once and expires after 7 days. Open invitations are listed under Open invitations. If a link is lost or went to the wrong person, revoke it and add the person again.

Changing roles and removing members

  • Change a member's role in the table and click Save.
  • Remove takes away the person's access to this workspace immediately. Their account remains, along with any other workspaces they belong to.

Some limits keep a workspace safe:

  • the Owner role cannot be given here;
  • only an owner can change or remove another owner;
  • nobody can change their own role or remove themselves.

Every change is recorded in the Audit log.

Signing in securely

Under Account security:

  • Two-factor sign-in: scan the QR code with an authenticator app and confirm with a code. Store the recovery codes somewhere safe; each one works once if you lose your phone.
  • Sessions: Sign out other sessions ends every session except the current one, for example after using a shared computer.

Further protection:

  • repeated wrong passwords are slowed down and limited;
  • sessions end after a period of inactivity;
  • every sensitive action is recorded in the Audit log.

Your data

  • All SEO data stays in your own database on your server.
  • Passwords are stored only as secure hashes. Google and DataForSEO credentials, and two-factor secrets, are stored encrypted.
  • SEO Control Center contacts only these services:
    • Google, for Search Console;
    • DataForSEO, if connected;
    • the license server, about once a week: licence key, installation ID, domain and version, never SEO data.