Teams and audit log
On the Team plan, one owner shares the plan with up to 10 people and sets what their AI coding agents may install.
Create a team
On the Team page, name the team (1 to 60 characters) and create it. Only an account on the Team plan can create one, and each account can own one team.
Members
Add members by GitHub username. Someone who hasn't signed in to dagsec yet appears as invited, and joins when they first sign in. The team has 10 seats in total.
Members get the Team plan's limits on their own account while they are in the team. Removing a member returns them to their own plan.
AI agent install policy
The owner sets one policy for every member's Claude Code plugin, Cursor hook, Gemini CLI hook and MCP checks:
| Setting | Options | Default |
|---|---|---|
| Stop installs of packages with | critical and high vulnerabilities, critical vulnerabilities, or nothing (off) | critical and high |
| Also stop packages that don't exist | on or off | on |
| Stop packages under these licenses | comma-separated SPDX IDs, up to 20, such as GPL-3.0, AGPL-3.0 | none |
| When an install is stopped | block it, or ask the developer | block |
The team's setting overrides each member's own plugin mode. License matching follows the rules in License policy. Members see the policy on their Team page but can't change it.
Audit log
Every install a member's agent attempts is logged:
| Column | Example |
|---|---|
| When | 5m ago |
| Member | @alice |
| Packages | npm lodash@4.17.4 |
| Decision | Allowed, Blocked or Asked |
Only the owner sees the log. Entries are kept for 90 days.
Delete a team
Deleting the team returns every member to their own plan and deletes the audit log.