FEATURES / Team Access

/// Team Access

Give your team access. Control exactly what they can do.

Invite teammates to your workspace with role-based permissions. No IAM policy changes. No shared credentials. Revoke access in seconds.

Start for free
Team membersstorafleet-workspace · 5 members+ Invite memberMEMBERROLESTATUSJOINEDACTIONSSRSurya R.surya@company.comOwnerActiveOwner since '23EditAKArjun K.arjun@company.comAdminActiveMar 2024EditPLPriya L.priya@company.comEditorActiveJan 2025EditMTMarco T.marco@company.comViewerActiveFeb 2025EditSCSarah C.sarah@contractor.ioViewerPendingInvited Feb 12ResendRevokeInvite a teammatecolleague@company.comViewer ▾Send inviteThey'll receive an email link to accept. No IAM changes required.

Add someone to your workspace in 30 seconds. Remove them in one click.

/// How it works

01

Connect your AWS account

Add your AWS credentials to the workspace once. They're encrypted with AES-256-GCM — team members never see them.

02

Invite teammates by email

Send an invite link to any email. They create a Storafleet account, accept the invite, and immediately have access at the level you assigned.

03

Assign roles, revoke any time

Set each member's permission level: Viewer, Editor, or Admin. Change it at any time. Revoke in one click — no IAM cleanup required.

Invite by email, not IAM

Send a workspace invite to any email address. The invitee creates an account, accepts, and they're in — no AWS IAM policy changes needed.

Four clear permission levels

Viewer (browse + download), Editor (upload + delete + lifecycle), Admin (everything except billing), Owner (full control). Assign the right level. Change it any time.

Encrypted credential vault

Your AWS credentials are encrypted with AES-256-GCM using a per-user derived key. Team members operate on your buckets without ever seeing your Access Key or Secret.

Revoke in one click

Remove a team member and their access is gone immediately. No IAM policy update. No key rotation. No manual cleanup.

Pending invites you can track

See which invites have been accepted, which are pending, and which have expired. Resend or revoke with one click.

Audit logs

Track who uploaded, deleted, or changed settings — and when. Full audit trail for compliance and incident review. (Business plan)

/// Without Storafleet

Giving a teammate S3 access means creating an IAM user, writing a policy, generating keys, and sharing them somehow.

  • Create an IAM user — navigate to IAM, configure settings, set permissions
  • Write a bucket policy or inline IAM policy in JSON
  • Generate access key and secret — then figure out how to share them securely
  • When they leave, manually revoke IAM access, rotate keys, audit bucket policies
  • No way to see what they've done without pre-configured CloudTrail

/// With Storafleet

An email invite, a role selection, and a send button. They're in. No IAM console required.

  • Invite by email — Storafleet handles authentication, no IAM changes
  • Role-based permissions: Viewer, Editor, Admin — no JSON policy
  • Team members never see your AWS keys — they operate via Storafleet sessions
  • Revoke in one click — access stops immediately, no key rotation
  • Audit log shows every action per member, per object (Business plan)

/// Permission levels

Right-sized access. Not all-or-nothing.

ActionViewerEditorAdminOwner
Browse & search objects
Download objects
Generate presigned URLs
Upload objects
Delete objects
Edit object metadata
Create lifecycle rules
Manage team members
View audit logs
Add / remove AWS credentials
Delete workspace

/// Credential security

Your AWS keys are encrypted. Always.

When you connect an AWS account, your Access Key ID and Secret Access Key are encrypted before they touch our database — using AES-256-GCM with a per-user key derived via HKDF-SHA256. The same algorithm used in TLS 1.3.

Team members who accept your workspace invite operate on your buckets through Storafleet's backend. They never receive, see, or store your AWS credentials. Access is managed by Storafleet session tokens — revocable in one click.

  • AES-256-GCM encryption at rest
  • Per-user derived keys via HKDF-SHA256
  • Never stored in plaintext. Never exposed to the frontend.
  • Team members never see your Access Key or Secret
  • Revoke workspace access instantly — no key rotation needed
AES-256-GCM🔑ENCRYPTEDPER-USER KEYHKDF-SHA256

/// When you'll use this

DevOps Engineer01

Onboarding a new engineer

Your newest hire needs read access to the staging bucket and write access to the dev bucket. You invite them by email, assign Editor to dev and Viewer to staging. Done in 90 seconds. No IAM console, no policy JSON.

Key featurePer-role invite + instant access

SaaS Founder02

Giving a client access to their assets

A client wants to download their files directly. You invite them as a Viewer. They can browse and download — nothing else. When the project ends, you revoke in one click.

Key featureViewer role + instant revocation

Agency Developer03

Temporary contractor access

A contractor needs to upload assets to a specific bucket for 2 weeks. You invite them as an Editor, scoped to that bucket. When the project wraps, one click removes their access. No key rotation needed.

Key featureEditor role + time-limited revocation

Your storage estate deserves a control plane.

Join the DevOps teams and founders who run every cloud's buckets from one control plane.

Free plan  ·  No credit card  ·  50+ cloud providers  ·  Cancel any time