For SponsorsUpdated May 2026

Team Members and Audit Log

Invite teammates with admin or member roles. Review every action in the 12-month audit log.

Team and audit at a glance

Two surfaces work together on Sponsor Studio. The team page is who has access to your sponsor account. The activity log is what they did once they got in. One answers who, the other answers what happened.

You invite teammates by email and assign a role. Every change to the account flows into a single, sponsor-scoped log with date, actor, category, and target. Filter the log by category or pull a CSV when an auditor asks.

Plan requirement

Multi-user team access and the activity log are Sponsor Studio features. Sponsor Pro and free sponsor accounts see an upgrade prompt on the team page and the activity log. Your Studio plan also defines how many users you hold on the account.

Inviting a team member

Open /sponsor/settings/team. The Invite Team Member card sits at the top.

1

Enter the email

Type the address of the person you want to add. The email is how they receive the invitation and how Fanflet matches them to the seat once they sign in.

2

Pick a role

Choose Admin, Campaign Manager, or Viewer. Default is Viewer. Roles are explained in the next section and you change them later from the same page.

3

Send the invite

Hit Invite. Fanflet creates a pending invitation, sends the recipient an email with a one-time link, and writes an invite_team_member entry to your activity log. The invitation expires after seven days if no one accepts.

Pending invitations show under their own card on the team page with the invitee email, role, and expiry date. Hit Revoke to cancel a pending invitation before the recipient accepts.

Roles

Three roles sit alongside the account Owner. Owner is the original account holder and has every permission by default.

  • Admin. Full access. Manages team members, campaigns, the resource library, brand settings, integrations, and billing. Admins invite, remove, and re-role other team members.
  • Campaign Manager. Creates and edits campaigns and library resources. No team management, no billing, no integration credentials.
  • Viewer. Read-only on the dashboard, analytics, and leads. Useful for execs, agency partners, or compliance reviewers who need visibility without write access.

Only Owners and Admins reach the team page. Campaign Managers and Viewers see a notice if they navigate to it directly.

Accepting an invitation

The invitee clicks the link in their email and lands on a Fanflet accept page. From there:

  • If they already have a Fanflet account on the same email, they sign in and the seat attaches automatically. They land on the sponsor dashboard.
  • If they are new, they set a password, the account gets created, and the seat attaches in the same step.
  • If they are signed in under a different email, the page asks them to sign out and return with the right address. Email and invitation address have to match exactly.

Expired or already-used links show a friendly error. Ask an admin to send a fresh invite from the team page.

Removing a team member

From the Team Members card, hit the trash icon next to the person you want to remove. Their access ends immediately. The next time they load a sponsor page, they get redirected.

Past work stays. Library resources they uploaded, campaigns they edited, and leads they exported keep their original timestamps and references. Removal revokes access going forward, not history.

A Viewer or Campaign Manager who wants to leave on their own asks an Admin to remove them, or removes themselves through the API. Admins demote first if you want to keep someone around at a lower permission instead of cutting access entirely.

The activity log

Open /sponsor/audit-log. The page lists the most recent 200 events with category badge, action label, target, and timestamp. Click Export CSV for the full retention window.

Events fall into eight categories.

  • Settings. Profile updates, logo changes, brand fields.
  • Team. Invitations sent, role changes, members removed, invitations revoked.
  • Campaigns. Campaigns created, updated, or deleted.
  • Connections. Speaker connections accepted, declined, or ended.
  • Library. Resources created, updated, or removed.
  • Leads. Lead exports.
  • Integrations. HubSpot, Zapier, and other integrations added or removed.
  • Speakers. Speaker seat invitations sent, resent, revoked, or removed.

Retention

Entries stay in the log for 12 months from the date the event happened. A nightly cleanup function purges records older than that. Export to CSV before the window closes if you need a longer retention horizon for compliance archives.

Filtering and exporting

The category dropdown above the event list narrows the view to one category at a time. The page shows a count of matching events as you filter.

Export CSV pulls every event from the past 12 months, up to 10,000 rows, with these columns: Date, Action, Category, Target Type, Target ID, Details. The file downloads with a date-stamped name like audit-log-2026-05-08.csv.

Use the CSV in a spreadsheet for date-range filtering, actor rollups, or reconciliation against a SIEM. Each row is a single immutable event.

Why this exists

Vendor security reviews ask whether you log administrative actions and how long you keep them. The activity log answers both questions on the spot.

Internal accountability is the other side. When a campaign goes live unexpectedly, a connection drops, or an integration disappears, the log tells you who did it and when. No guessing, no Slack archaeology.

Related reading