MentionFlow AI

Team and security

Client-safe workspaces with a paper trail

Four roles, with read-only client viewers the server enforces. Access per project. Single-use invites that confirm before they join. Two-factor auth. An audit log you can see. And export or delete of all your data, self-serve.

Roles

4

owner, admin, member, client viewer. The server enforces them

Invites

Single use

expire in 7 days, confirm before joining, never grant owner

Two-factor

TOTP

with backup codes, on every plan. Verifies before it turns on

Your data

Export or delete

one zip with a manifest. Delete is owner-only, typed to confirm

Roles and client viewers

Read-only means enforced, not hidden

Owner, admin, member, and client viewer. The viewer is the read-only seat an agency gives a client for a live view of their reports. The server decides write access from the role. A viewer who reaches an edit action is stopped everywhere, not just in the UI.

The same fence binds us. An operator in support view holds no membership in your workspace, so member, invite, role and scope controls are read-only for them too. Every support view-as session lands in your audit log.

settings / members and roles
Ownereverything, including billing and ownership
Adminmembers, API keys, billing
Memberread and write on workspace data
Client viewerread-only, per project

Sample. The server decides write access from the role, not from hidden buttons.

Invites and per-project access

Single-use invites, limited to the projects you choose

Invites are single-use links that expire after seven days. We can email them for you, and we say "sent" only after the email provider accepts the message. Opening a link shows the workspace, the role and the account. Nothing happens until the person confirms. Seat caps are checked again at that moment, so invites can never overfill a plan.

Members and client viewers can be limited to chosen projects. We refuse to make a "scoped admin", because a line an admin could lift on themselves is not a line.

invite / confirm before join

Join Northwind Agency?

as Client viewer, limited to ClickUp

signed in as [email protected]

Join workspaceCancel

Sample. Opening a link never enrolls anyone. Joining takes a click.

Audit log

Every access change on the record, and you can see it

The audit log lives in your workspace settings, not in a support queue you have to ask about. One firm rule: an invite acceptance is recorded together with the membership it grants, so a new member can never join unaudited.

Recorded
Membership
role changes, project changes, removals
Invites
created, emailed, accepted (together with the grant), revoked
Credentials
API keys created and revoked, password resets, email verifications
Data leaving
data exports, report schedule changes, Cloudflare Worker connect and disconnect
Operator access
support view-as sessions. Visible to you, not just to us
Destructive
brand archive, restore, delete, workspace deletion, billing changes

Account security

Two-factor auth that cannot lock you out

TOTP two-factor with one-time backup codes, on every plan. It does not switch on until a code from your authenticator actually verifies. Turning it off, or making new backup codes, takes a code that is valid right now.

Actions that move workspace data out (creating an API key, turning on a report schedule, setting a notification webhook) also need a verified email address, for accounts created on or after 2026-07-11.

account / two-factor auth
471902

Backup codes show once at setup. Each works one time.

Sample. TOTP with one-time backup codes. It verifies before it turns on.

GDPR self-serve

Your data leaves with you. No ticket needed.

Export downloads everything the workspace owns as one zip: full answer texts, mentions, citations, metrics, prompts, members, the audit log. A manifest says the date and exactly what is and is not inside.

Delete is owner-only and typed to confirm. Any active subscription is cancelled with Stripe first. If that cannot be confirmed, nothing is deleted. Then every project, answer, metric, member, key, and the audit trail itself is erased in one step.

danger zone / export bundle
answers, mentions, citationsdaily metricsprompts and competitorsmembers and invitesaudit logmanifest.json

Sample. One zip with a manifest that says exactly what is and is not inside.

Frequently asked questions

What roles does MentionFlow support?

Four. Owner (everything, including billing and handing over ownership). Admin (members, API keys, billing). Member (read and write on workspace data). Client viewer (read-only). The server decides write access from the role. Hiding a button is never the only thing between a viewer and a change.

Can I give a client access to just their own project?

Yes. Members and client viewers can be limited to specific projects, on the invite or later. Owners and admins always see the whole workspace. We refuse to make a "scoped admin" on purpose: access runs on role, and a scoped admin could simply un-scope themselves. The line is real, not cosmetic.

How do invites work?

Every invite is a single-use link that expires after seven days, for a role you choose (never owner). Opening it shows a confirmation screen with the workspace, the role, and the signed-in account. Nothing happens until the person clicks to confirm. Seat caps are checked again at that moment, so a burst of invites can never overfill a plan. Every acceptance is written to the audit log together with the membership it grants.

Is there an audit log?

Yes, and you can see it. Role and project changes, removals, invites created, emailed, accepted and revoked, API keys created and revoked, report schedule changes, password resets and email verifications, billing events, Google Search Console connect and disconnect, support view-as sessions, Cloudflare Worker connect and disconnect, data exports, brand archive, restore and delete, and workspace deletion.

Does MentionFlow support two-factor authentication?

Yes. TOTP two-factor with one-time backup codes, on every plan. It does not switch on until you enter a valid code from your authenticator, so a misconfigured app cannot lock you out. Turning it off, or making new backup codes, takes a code that is valid right now.

Can I export or delete all my data (GDPR)?

Both are self-serve. Export downloads everything the workspace owns as one zip: answers, mentions, citations, metrics, prompts, members, the audit log. A manifest says exactly what is and is not inside. Delete is owner-only with typed confirmation. Any active subscription is cancelled with Stripe first, then everything is erased in one step.

The mechanics are in the docs: Workspace and members, Two-factor authentication and API keys. Client-safe workspaces pair with client reporting and the API and MCP server.

Run client work without handing over the keys

Roles, limited access, and an audit trail your clients can see too.

Start 7-Day Trial