Buskara
Help center

Team and security

Roles and invitations, two-factor authentication, and the two protections the team is never allowed to work around.

3 min Updated 9 August 2026

The three roles

Everyone on the team has an account of their own (never share your access) and a role that decides what they can do:

Owner Admin Member
See dashboard, analytics, export CSV, use the playground
Rules, synonyms, assistant, API keys, store settings ·
Invite and manage the team · ·
Plan, packs, services, billing details · ·

The logic: whoever consults sees everything, whoever operates writes, and the purchases belong to whoever pays. The owner comes with the account and isn't invited; the account always has to have at least one.

Inviting somebody

In Account → Team → Invitations (owner only): an email and a role (Admin or Member). The invitation generates a link that appears only once, right after creating it: copy it and send it to the person yourself, through whichever channel you prefer. The platform doesn't send invitation emails.

Worth knowing:

  • The link is valid for 7 days. Once it expires, you create another; re-inviting the same email replaces the previous invitation.
  • An invitation isn't edited: you revoke it and make another. Revoking invalidates the link immediately.
  • An email that already has an account on another store can't be invited; each account belongs to one store only.

Whoever gets the link opens it, writes their name and chooses a password (the email comes from the invitation and can't be changed) and joins the team straight away, with the role assigned.

On the Team page, each member's role is changed in the selector on the list itself, and it saves when you choose. Two fixed protections: nobody removes themselves, and the last owner is neither demoted nor removed.

Two-factor authentication

In your profile (the user menu) you can turn on the second factor by authenticator app (TOTP: 1Password, Google Authenticator, Aegis, among others). Never by SMS and never by email: email is the same channel the password is reset through, and a second factor on the same channel isn't a second factor.

Turning it on has two steps, deliberately: first you read the QR with the app, then you confirm with a code it generates. Only at the confirmation does 2FA take effect; that way, a badly read QR doesn't lock anyone out of the account.

With the confirmation come recovery codes, shown only once: keep them off the phone (in a password manager, for example). Each one works once only and is there to get you in when the app isn't available. You can generate a new batch at any time; it asks for the password and invalidates the old ones on the spot.

When logging in with 2FA, the code field takes both the TOTP and a recovery code. Turning 2FA off asks for the password.

What about the data?

What the platform keeps about your store, what can be downloaded and what can be deleted is in privacy and data.

Was this guide useful?

No, I still have questions