# Invite teammates with subaccounts

**Subaccounts** let you share one HostTracker account with your team without sharing a single login. Each
teammate signs in with their own credentials, scoped to exactly what they're allowed to do. Subaccounts are
available on plans that include the feature - see [Plans and packages compared](/account/plans/).

## Rights reference

Access is split by area, each with a separate **view** and **edit** right, so you can give someone visibility
without letting them change anything.

| Area | View right | Edit right | What edit lets them do |
|---|---|---|---|
| Monitors | See monitors and their results | Create, edit, pause and delete monitors | Full monitor management |
| Contacts | See contacts and subscriptions | Create, edit and delete contacts | Full contact management |
| Status pages | See status pages | Create, edit and delete status pages, and publish incidents | Manage public-facing status pages independently of monitor edit rights |
| Billing | See plan, invoices and usage | Change plan, payment methods | Full billing control |
| Profile | - | Edit account-wide profile settings | (no separate view right - edit implies it) |

Two additional standalone rights:

- **API access** - the subaccount can mint and use its own API tokens.
- **Manage subaccounts** - the subaccount can invite, edit or remove other subaccounts.

Grant the narrowest set a teammate needs - for example view-only on monitors and contacts for someone who just
needs to check status, or edit-monitors without billing access for someone who manages checks but shouldn't see
invoices. Status pages have their own pair deliberately: publishing an incident at 3am doesn't require handing
someone edit rights over every monitor in the account.

## Set it up in the app

1. Open **Access** (from the top-right menu).
2. Click **Invite**.
3. Enter the teammate's email address.
4. Choose the rights to grant from the table above.
5. Send the invite. The teammate confirms it to activate their sign-in.

### Editing or removing access

Open **Access**, select the subaccount, and change its rights or remove it. Removing a subaccount doesn't
affect any monitors, contacts or status pages it created - those stay on the main account.

## What happens next

A subaccount signs in with its own email and password, on a browser-length session (not the 30-day persistent
session a full account gets). Every API call or app action it takes is checked against the rights above -
missing the right one is refused, not silently limited. A subaccount's cookie session carries the **super
account's** user id, so a subaccount cannot use a monitors-view-only grant to see billing data through the API
either - the same rights gate both the app and the API.

## Limits and gotchas

- Subaccount management itself is an **app-only** feature today - there is no public REST API or MCP tool for
  inviting or editing subaccounts; only the account owner (or a subaccount granted "Manage subaccounts") can
  do it, from **Access**.
- A right you don't grant is enforced as a hard refusal, not a read-only fallback - a subaccount without
  Contacts view sees no contacts at all, not a greyed-out list.
- How many subaccounts your plan allows is a plan entitlement - see [Plans and packages compared](/account/plans/).

## Related

- [Account & billing overview](/account/overview/)
- [API authentication, tokens and scopes](/integrations/api-authentication/)
