Team Sharing & Roles
Sharing specific 2FA accounts with subteams
Pair2FA Security Team
·Updated 6 days ago
·3 min read
Restrict sensitive production keys to authorized engineering leads while sharing dev keys broadly.
Granular Vault Sharing
Not every team member needs access to root production credentials. Pair2FA supports folder and tag-level access policies.
Configuring Subteam Restrictions
1. In Workspace Settings, navigate to Folders & Access Control.
2. Create a folder (e.g. #finance-vault or #prod-aws).
3. Assign specific team members or roles to the folder.
4. Members only see passcodes for accounts within their authorized folders.
Was this article helpful?
Let us know how we can improve our documentation.
RELATED ARTICLES IN THIS TOPIC
Inviting team members to your workspace
Send email invitations and set custom access permissions for your colleagues.
Read article
Difference between Viewer and Admin roles
Detailed RBAC comparison matrix between Viewer, Admin, and Workspace Owner roles.
Read article
Instantly revoking access when a teammate leaves
How 1-click offboarding protects your accounts without changing external 2FA seeds.
Read article
STILL NEED HELP?
Have questions?
Our support team is online 24/7 to help you configure 2FA for your organization.
Contact support