Docs
Roles & permissions
Four roles. The line that matters is between reading and changing production.
Obsevo's control plane can retry executions and deactivate live workflows, so "everyone who can see the dashboard can also act on it" stops being a defensible default the moment more than one person has an account.
| Role | Can |
|---|---|
| Viewer | Read everything. Change nothing |
| Analyst | Resolve incidents, set runbooks and SLA targets. No configuration, no control actions |
| Admin | Manage instances, alerts, clients and API keys, and run control actions against n8n |
| Owner | Everything an admin can, plus billing and managing members |
Roles are per workspace. There is no per-workflow permission model, and no seat limit on any plan — including the free tier.
Invites
Members are invited by email from Settings → Members. An invite is a single-use token that expires; accepting it while signed in attaches the account to the workspace, and accepting while signed out prompts for sign-up first.
Audit log
Configuration changes and control actions are recorded with the actor, the target and the outcome, under Settings → Audit. It is not a general activity feed: reads are not recorded, only changes.