Skip to main content

Membership

Access follows team membership. A person who joins a team can query every datasource that team owns; removing them from the team removes that access immediately. If two groups need different slices of the same database, give them separate teams and separate datasources with different exposure rules, rather than one shared team.

Adding people

Invite by email from the team settings page. Invitations are scoped to a single team.

Removing access

Removing someone from a team revokes their access at once — in-flight sessions included. To cut off a whole datasource, disable it in the dashboard; to cut off TeamDuo entirely, revoke the database role’s grants.

Auditing

Every query is recorded with the datasource, the requesting member, the statement, and whether it was allowed or refused. Review the log when you widen exposure, so you can see what the new surface is actually used for.