UPVALE / GUIDES
Team and account
Manage organization roles, invitations, sign-in sessions, your profile, and account security.
On this page
Organization settings control who can manage your resources. Your profile controls your own name, sign-in security, and date preferences.
Create an account and sign in
If account registration is available, enter your name, email, and a password of at least 12 characters on Create your account, then select Create account. Open the verification email and follow its button. The confirmation page tells you whether you can sign in or need to wait for account approval.
Use Resend verification email if the verification link has expired. If registration is disabled or your selected package opens a signup placeholder, contact Upvale for access; the package placeholder does not complete a purchase or create an account.
Sign in with your email and password. If two-factor authentication is enabled, enter your authenticator code or a recovery code when prompted. If you do not yet belong to an organization and the dashboard offers Create your organization, enter its name and select Create organization. An invited user joins the organization through the invitation instead.
Choose an organization
Open the account menu and use the Organization selector if you belong to more than one organization. Workloads, clusters, secrets, roles, and audit records belong to the selected organization. You can have different roles in different organizations.
Check the selected organization before inviting someone or changing infrastructure. Switching organization does not change your personal sign-in account.
Settings tabs
Open Settings in the sidebar:
| Tab | What you can do |
|---|---|
| Overview | See the organization name and your role. With View subscription, see the package, expiry, audit-log entitlement, and cluster, node, and active-user usage. |
| Roles | Create and edit roles and choose the permissions they grant. Requires Manage team. |
| Members | Manage active members and pending invitations in one place. Requires Manage team. |
| Sessions | Review your own sign-in sessions and sign out other devices. |
Plan usage distinguishes used capacity from reserved capacity. Pending work or invitations can reserve capacity before it is fully used. A limit shown as Unlimited has no numerical cap in that package.
Create a role
- Open Settings → Roles → New role.
- Enter a Role name and an optional Description.
- Select the permissions the person needs.
- Select Create role.
- Assign the role to an existing member or use it when sending an invitation.
The fixed organization Administrator role has all organization permissions. Custom roles can be edited or deleted. Move assigned members to another role before deleting their role.
You can grant only roles and permissions your own role is allowed to grant. The dashboard hides unavailable choices. Resource management permissions include the monitoring permission needed to view those resources.
Permission reference
| Permission | Allows |
|---|---|
| View monitoring | View dashboards, resource state, metrics, and operational status. |
| View logs | Read and download application, database, and scheduled-job logs. |
| Manage workloads | Create, edit, and remove projects, applications, and scheduled jobs. |
| Manage deployments | Deploy, roll back, start, stop, and restart workloads. |
| Manage databases | Create, configure, repair, restore, upgrade, and remove databases. |
| Manage nodes | Enroll, update, change, clean, and remove nodes. |
| Manage infrastructure | Manage clusters, networking, ingress, registries, and storage destinations. |
| Manage privileged workloads | Configure and operate workloads using host binds, Linux capabilities, or kernel settings. |
| Manage secrets | Create, rotate, use, and remove stored secrets; access database credentials and protected workload configuration. Generic secret values remain write-only in the Secrets screen. |
| Access terminals | Open interactive node and workload terminals. Other resource permissions may also be required for the target. |
| Access file manager | Browse, upload, download, edit, and remove files on nodes. |
| Manage Traefik | Read and change cluster Traefik configuration files. |
| Connect to developer VPN | Manage personal VPN devices for clusters where access has been granted. |
| Manage developer VPN | Choose gateways, define allowed network access, grant access, and manage VPN devices. |
| Manage alerts | Configure alert rules and notification channels. |
| View audit log | Read organization audit events and actor details, when the package includes audit logs. |
| Manage team | Manage roles, invite and remove members, and assign roles. |
| View subscription | Read the organization's package, limits, and usage. |
Permissions can work together. For example, creating a database requires database management and secrets access, while deploying a Compose definition requires workload, secrets, and deployment permissions. The relevant feature guide lists its requirements.
A role controls Upvale actions; it does not create database users or grant SQL permissions inside a database.
Invite a team member
- Open Settings → Members → Invite.
- Enter the person's Email.
- Choose their Role.
- Send the invitation.
- Check Pending invitations for the destination, role, and expiry.
A new user follows the email's invitation button, sets and confirms a password, then signs in. Someone who already has an account signs in with their existing password to accept the invitation. They should use the same email address that received it.
Resend or revoke an invitation
Use Resend next to a pending invitation to send a fresh link. The new email replaces the old invitation link; ask the person to use the latest message. Resending also renews the invitation expiry.
Use Revoke if the invitation is no longer needed. This prevents the pending invitation from being accepted. It does not remove someone who has already joined; use the active-member removal action for that.
If an invitation fails, check its email address and expiry, the organization's available user capacity, and whether your role can grant the selected role.
Change or remove an active member
In Members → Active members, choose a different value in the member's Role selector to update their role. Use the remove action to remove their membership from this organization.
Removing a membership does not delete the person's account or their memberships elsewhere. Upvale prevents removal or reassignment of the last active organization Administrator.
For a developer who needs database connectivity without infrastructure management, create a small role with Connect to developer VPN and only the other permissions they need. Separately grant access to the relevant cluster and network destinations. See Developer VPN for the complete setup; a VPN permission alone does not grant access to every cluster.
Review sessions
Open Settings → Sessions to see the browser, source IP, sign-in time, and expiry for your sessions. The current session is marked current.
Use a row's revoke action to sign out that other session, or select Sign out other sessions to keep only the session you are using. This page shows your sessions, not every member's sessions.
Update your profile
Open Profile from the account menu.
| Field | What it changes |
|---|---|
| Shows the account email; it is read-only here. | |
| First name, Last name | Updates your profile name. |
| Timezone | Uses the browser's timezone or a selected timezone for displayed dates and times. |
| Date and time format | Chooses the display format, with a preview. |
Select Save profile after editing. Display timezone preferences do not change a scheduled job's configured timezone.
The Developer VPN card opens your personal VPN access page, where you manage your devices and connection files for granted clusters.
Change your password
Under Password, enter your current password, new password, and confirmation. Select Change password. Other signed-in sessions are revoked after a successful change.
If you cannot sign in, use Forgot password on the login page and follow the reset link sent to your account email. For an unused invitation, open the invitation link and complete password setup instead. If the link expired, ask the inviter to resend it.
Enable two-factor authentication
- Open Profile → Two-factor authentication → Enable 2FA.
- Enter your current password and select Continue.
- Scan the QR code with an authenticator app, or enter the manual setup key in that app.
- Enter the current authenticator code and select Enable 2FA.
- Save the recovery codes somewhere you can access if you lose the authenticator.
Future sign-ins use your password plus an authenticator code or a recovery code. Recovery codes are single-use. The profile shows how many remain.
New recovery codes requires your password and an authenticator or recovery code. The new set replaces the previous set. Disable 2FA also requires your password and an authenticator or recovery code.
Theme and navigation
Upvale initially follows your system's light or dark appearance. Use the theme button to select the other appearance; that choice is remembered by the browser.
The header search finds resources in your current organization. Favorites keep frequently used projects and resources close at hand. The documentation link opens these guides from the control plane.
For operational records, see Monitoring, alerts, and audit.