Give your team and clients the right access, nothing more
A clear role model, real two-factor security and masked personal data, with team seats that are always free because you pay for sites, not logins.
At a glance
- Three roles that map to how agencies actually work: Principal, Agents and client Owners.
- Permission-based access control, so people see and do exactly what their role allows.
- TOTP two-factor authentication and Google single sign-on on every login.
- Personal data masked by default, with every reveal audit-logged.
- Team seats are free; billing is per monitored site, never per user.
Shared logins and all-or-nothing access are a liability
The moment more than one person touches your monitoring, access becomes the hard part. Your account owner needs full control, your team needs to do real work without holding the keys to billing and deletion, and your clients should see their own site's activity and nothing else. VigilDeck builds all three into a role model designed around how contractors and agencies actually operate.
On top of that structure sits security you'd expect from a system that holds an audit trail: two-factor authentication, single sign-on, and personal data that stays masked until someone with the right role deliberately reveals it. And because seats are free, you never have to ration logins or leave a client off the account to save money.
Most teams handle access badly because the tools make it expensive or clumsy to do it well. A single shared login gets passed around, so the audit trail can't tell you who actually did anything. That defeats the entire purpose of keeping a record in the first place.
The alternative is usually all-or-nothing. Either someone is an admin with full rights, including billing and the power to delete a site, or they're locked out of the work they need to do. Neither fits a team where a junior contractor should add and rotate sites but never delete one, or a client who should read their own logs but touch nothing else.
Then there's the money. When a platform charges per seat, every teammate and every client login has a price tag, so people quietly under-provision: shared accounts, unnamed logins, clients who never get access. Each shortcut chips away at accountability, which is exactly what a monitoring platform is supposed to protect.
A role model that matches your org chart
Every person gets a role scoped to what they actually need to do.
Principal
The account owner with full rights: manage billing, add and delete sites, invite and remove people, and reveal masked personal data. There's one clear owner of the account, not a vague pool of admins.
Agents
Your team members. Agents can view sites, add and rotate sites, and see the team, but they cannot delete sites, delete the account, manage billing or invite others. Real work, without the keys to everything.
Owners
Your clients. Each Owner gets a site-scoped, read-only login to just their own site's activity, so they can see what's happening without any access to your other clients or your account.
Permission-based RBAC
Access is governed by permissions tied to roles, not by trust and good intentions. What a person can see and do follows their role consistently across every part of the platform.
Masked personal data
Email and mobile numbers are masked by default. Only a Principal, or an Agent they delegate, can reveal them, so personal contact details aren't sitting in plain view for everyone on the account.
Audit-logged reveals
Every time masked personal data is revealed, the action is recorded. Sensitive access leaves a trail, which is exactly what you want from a platform built around accountability.
How you set up your team
Start as Principal
The person who creates the account is the Principal, with full rights over billing, sites, people and data. This is the single accountable owner of everything under the account.
Invite your team as Agents
Add teammates as Agents so they can view, add and rotate sites and see the team, while billing, deletion and invitations stay with you. Every seat you add costs nothing.
Give clients Owner access
Invite each client as an Owner with a read-only, site-scoped login to their own site's activity. They get transparency into their site and no visibility into anyone else's.
Lock it down
Turn on TOTP two-factor and Google single sign-on, keep personal data masked, and let the role model and audit log handle the rest as your team and client list grow.
Why the model works
Invite everyone, pay for none
Team seats are free. Because you're billed per monitored site and never per login, you can add your whole team and every client without a per-seat bill quietly punishing you for good access hygiene.
Real accountability
Unique email and mobile per user plus role-scoped permissions mean the audit trail names actual people. When something changes, you know who, not just "the shared admin login".
Security built in
TOTP two-factor authentication and Google single sign-on protect every account, and masked personal data with logged reveals keeps sensitive details out of everyday view.
Client-ready reporting
On the Agency plan, white-label and branded client reports let you hand clients a polished view of their site's activity under your own name.
Who uses it this way
-
Agencies with contractors
The founder holds the Principal role while contractors work as Agents who can add and rotate sites but can't delete them, manage billing or invite people. The blast radius of a mistake or a departing contractor stays small.
-
Teams that need client transparency
Every client gets an Owner login into their own site's activity, read-only and site-scoped. Clients get real visibility, you keep every other account private, and it costs you nothing per login.
-
Security-conscious operators
Two-factor authentication, single sign-on, masked personal data and audit-logged reveals mean access and sensitive data are governed and traceable, which matters when the platform is your source of truth.
Related monitoring features
Team Management: frequently asked questions
Do extra team members or clients cost more?
No. Team seats are always free. VigilDeck bills per monitored site, so whether one person or twenty log in, and however many client Owners you add, your cost is tied to sites, not logins. See pricing for the per-site details.
What exactly can an Agent not do?
Agents can view sites, add and rotate sites, and see the team. They cannot delete sites, delete the account, manage billing or invite other people. Those rights stay with the Principal, so a teammate can do real work without holding account-ending powers.
What do my clients see?
Clients are Owners with a read-only login scoped to just their own site's activity. They can follow what's happening on their site and have no access to your other clients, your team or your account settings.
How is personal data protected?
Email and mobile numbers are masked by default. Only a Principal, or an Agent the Principal delegates, can reveal them, and every reveal is audit-logged. Sensitive contact details aren't exposed to everyone on the account by default.
What login security is available?
VigilDeck supports TOTP two-factor authentication and Google single sign-on, and each user has a unique email and mobile. That combination keeps accounts protected and keeps the audit trail tied to real, distinct people.
Can I send clients branded reports?
Yes, on the Agency plan. White-label and branded client reports let you present a client's site activity under your own brand instead of VigilDeck's.
Bring your whole team on board for free
Give your team the right access and your clients their own view, and only ever pay per site.
Free for up to 3 sites · No credit card required · Cancel anytime