FEATURES / Team Access
/// Team Access
Give your team access. Control exactly what they can do.
Invite teammates to your workspace with role-based permissions. No IAM policy changes. No shared credentials. Revoke access in seconds.
Start for freeAdd someone to your workspace in 30 seconds. Remove them in one click.
/// How it works
Connect your AWS account
Add your AWS credentials to the workspace once. They're encrypted with AES-256-GCM — team members never see them.
Invite teammates by email
Send an invite link to any email. They create a Storafleet account, accept the invite, and immediately have access at the level you assigned.
Assign roles, revoke any time
Set each member's permission level: Viewer, Editor, or Admin. Change it at any time. Revoke in one click — no IAM cleanup required.
Invite by email, not IAM
Send a workspace invite to any email address. The invitee creates an account, accepts, and they're in — no AWS IAM policy changes needed.
Four clear permission levels
Viewer (browse + download), Editor (upload + delete + lifecycle), Admin (everything except billing), Owner (full control). Assign the right level. Change it any time.
Encrypted credential vault
Your AWS credentials are encrypted with AES-256-GCM using a per-user derived key. Team members operate on your buckets without ever seeing your Access Key or Secret.
Revoke in one click
Remove a team member and their access is gone immediately. No IAM policy update. No key rotation. No manual cleanup.
Pending invites you can track
See which invites have been accepted, which are pending, and which have expired. Resend or revoke with one click.
Audit logs
Track who uploaded, deleted, or changed settings — and when. Full audit trail for compliance and incident review. (Business plan)
/// Without Storafleet
Giving a teammate S3 access means creating an IAM user, writing a policy, generating keys, and sharing them somehow.
- Create an IAM user — navigate to IAM, configure settings, set permissions
- Write a bucket policy or inline IAM policy in JSON
- Generate access key and secret — then figure out how to share them securely
- When they leave, manually revoke IAM access, rotate keys, audit bucket policies
- No way to see what they've done without pre-configured CloudTrail
/// With Storafleet
An email invite, a role selection, and a send button. They're in. No IAM console required.
- Invite by email — Storafleet handles authentication, no IAM changes
- Role-based permissions: Viewer, Editor, Admin — no JSON policy
- Team members never see your AWS keys — they operate via Storafleet sessions
- Revoke in one click — access stops immediately, no key rotation
- Audit log shows every action per member, per object (Business plan)
/// Permission levels
Right-sized access. Not all-or-nothing.
| Action | Viewer | Editor | Admin | Owner |
|---|---|---|---|---|
| Browse & search objects | ✓ | ✓ | ✓ | ✓ |
| Download objects | ✓ | ✓ | ✓ | ✓ |
| Generate presigned URLs | ✓ | ✓ | ✓ | ✓ |
| Upload objects | — | ✓ | ✓ | ✓ |
| Delete objects | — | ✓ | ✓ | ✓ |
| Edit object metadata | — | ✓ | ✓ | ✓ |
| Create lifecycle rules | — | ✓ | ✓ | ✓ |
| Manage team members | — | — | ✓ | ✓ |
| View audit logs | — | — | ✓ | ✓ |
| Add / remove AWS credentials | — | — | — | ✓ |
| Delete workspace | — | — | — | ✓ |
/// Credential security
Your AWS keys are encrypted. Always.
When you connect an AWS account, your Access Key ID and Secret Access Key are encrypted before they touch our database — using AES-256-GCM with a per-user key derived via HKDF-SHA256. The same algorithm used in TLS 1.3.
Team members who accept your workspace invite operate on your buckets through Storafleet's backend. They never receive, see, or store your AWS credentials. Access is managed by Storafleet session tokens — revocable in one click.
- AES-256-GCM encryption at rest
- Per-user derived keys via HKDF-SHA256
- Never stored in plaintext. Never exposed to the frontend.
- Team members never see your Access Key or Secret
- Revoke workspace access instantly — no key rotation needed
/// When you'll use this
Onboarding a new engineer
Your newest hire needs read access to the staging bucket and write access to the dev bucket. You invite them by email, assign Editor to dev and Viewer to staging. Done in 90 seconds. No IAM console, no policy JSON.
Key featurePer-role invite + instant access
Giving a client access to their assets
A client wants to download their files directly. You invite them as a Viewer. They can browse and download — nothing else. When the project ends, you revoke in one click.
Key featureViewer role + instant revocation
Temporary contractor access
A contractor needs to upload assets to a specific bucket for 2 weeks. You invite them as an Editor, scoped to that bucket. When the project wraps, one click removes their access. No key rotation needed.
Key featureEditor role + time-limited revocation
Your storage estate deserves a control plane.
Join the DevOps teams and founders who run every cloud's buckets from one control plane.
Free plan · No credit card · 50+ cloud providers · Cancel any time