Team and security
Client-safe workspaces with a paper trail
Four roles, with read-only client viewers the server enforces. Access per project. Single-use invites that confirm before they join. Two-factor auth. An audit log you can see. And export or delete of all your data, self-serve.
Roles
4
owner, admin, member, client viewer. The server enforces them
Invites
Single use
expire in 7 days, confirm before joining, never grant owner
Two-factor
TOTP
with backup codes, on every plan. Verifies before it turns on
Your data
Export or delete
one zip with a manifest. Delete is owner-only, typed to confirm
Roles and client viewers
Read-only means enforced, not hidden
Owner, admin, member, and client viewer. The viewer is the read-only seat an agency gives a client for a live view of their reports. The server decides write access from the role. A viewer who reaches an edit action is stopped everywhere, not just in the UI.
The same fence binds us. An operator in support view holds no membership in your workspace, so member, invite, role and scope controls are read-only for them too. Every support view-as session lands in your audit log.
Sample. The server decides write access from the role, not from hidden buttons.
Invites and per-project access
Single-use invites, limited to the projects you choose
Invites are single-use links that expire after seven days. We can email them for you, and we say "sent" only after the email provider accepts the message. Opening a link shows the workspace, the role and the account. Nothing happens until the person confirms. Seat caps are checked again at that moment, so invites can never overfill a plan.
Members and client viewers can be limited to chosen projects. We refuse to make a "scoped admin", because a line an admin could lift on themselves is not a line.
Join Northwind Agency?
as Client viewer, limited to ClickUp
signed in as [email protected]
Sample. Opening a link never enrolls anyone. Joining takes a click.
Audit log
Every access change on the record, and you can see it
The audit log lives in your workspace settings, not in a support queue you have to ask about. One firm rule: an invite acceptance is recorded together with the membership it grants, so a new member can never join unaudited.
Account security
Two-factor auth that cannot lock you out
TOTP two-factor with one-time backup codes, on every plan. It does not switch on until a code from your authenticator actually verifies. Turning it off, or making new backup codes, takes a code that is valid right now.
Actions that move workspace data out (creating an API key, turning on a report schedule, setting a notification webhook) also need a verified email address, for accounts created on or after 2026-07-11.
Backup codes show once at setup. Each works one time.
Sample. TOTP with one-time backup codes. It verifies before it turns on.
GDPR self-serve
Your data leaves with you. No ticket needed.
Export downloads everything the workspace owns as one zip: full answer texts, mentions, citations, metrics, prompts, members, the audit log. A manifest says the date and exactly what is and is not inside.
Delete is owner-only and typed to confirm. Any active subscription is cancelled with Stripe first. If that cannot be confirmed, nothing is deleted. Then every project, answer, metric, member, key, and the audit trail itself is erased in one step.
Sample. One zip with a manifest that says exactly what is and is not inside.
Frequently asked questions
What roles does MentionFlow support?
Four. Owner (everything, including billing and handing over ownership). Admin (members, API keys, billing). Member (read and write on workspace data). Client viewer (read-only). The server decides write access from the role. Hiding a button is never the only thing between a viewer and a change.
Can I give a client access to just their own project?
Yes. Members and client viewers can be limited to specific projects, on the invite or later. Owners and admins always see the whole workspace. We refuse to make a "scoped admin" on purpose: access runs on role, and a scoped admin could simply un-scope themselves. The line is real, not cosmetic.
How do invites work?
Every invite is a single-use link that expires after seven days, for a role you choose (never owner). Opening it shows a confirmation screen with the workspace, the role, and the signed-in account. Nothing happens until the person clicks to confirm. Seat caps are checked again at that moment, so a burst of invites can never overfill a plan. Every acceptance is written to the audit log together with the membership it grants.
Is there an audit log?
Yes, and you can see it. Role and project changes, removals, invites created, emailed, accepted and revoked, API keys created and revoked, report schedule changes, password resets and email verifications, billing events, Google Search Console connect and disconnect, support view-as sessions, Cloudflare Worker connect and disconnect, data exports, brand archive, restore and delete, and workspace deletion.
Does MentionFlow support two-factor authentication?
Yes. TOTP two-factor with one-time backup codes, on every plan. It does not switch on until you enter a valid code from your authenticator, so a misconfigured app cannot lock you out. Turning it off, or making new backup codes, takes a code that is valid right now.
Can I export or delete all my data (GDPR)?
Both are self-serve. Export downloads everything the workspace owns as one zip: answers, mentions, citations, metrics, prompts, members, the audit log. A manifest says exactly what is and is not inside. Delete is owner-only with typed confirmation. Any active subscription is cancelled with Stripe first, then everything is erased in one step.
The mechanics are in the docs: Workspace and members, Two-factor authentication and API keys. Client-safe workspaces pair with client reporting and the API and MCP server.
Run client work without handing over the keys
Roles, limited access, and an audit trail your clients can see too.
Start 7-Day Trial