For business
ZRAZU for business
Control over a domain portfolio for a team: who can do what, what actually happened, and how to stop it if something goes wrong.
Team roles and access
You invite a person to one of the roles; what exactly each one allows is visible right in the account.
| Role | What it allows |
|---|---|
| Owner | Everything, including managing people, keys and the payment method. |
| Admin | Domains, DNS, certificates and money. |
| Tech | DNS and certificates; no access to money. |
| Accountant | Invoices, acts, balance; no access to DNS. |
| Read-only | See everything, change nothing. |
The exact rights of each role are to be announced. A person’s API key is never stronger than their role.
API keys under control
- A key is issued from a rights template, not “everything”: read-only, edit DNS, monitoring, auto-renew with a spend limit.
- A key is scoped to specific domains; for rights that spend money, a domain list is mandatory — “all, including future ones” isn’t available.
- A key’s conditions are an IP range and a monthly call or spend limit; going over answers with a code and when the limit resets.
- Rights in the “ownership and irreversible” class (remove the transfer lock, change nameservers) need confirmation by a second owner or a 24-hour wait before activation. A “Revoke all keys” button sits on the same screen.
- An assistant (a model) connects through OAuth, not a copied key: read-only by default, “money” rights are a separate checkbox with a limit, and “ownership and irreversible” rights are never granted through OAuth at all.
Action log
- Every domain has its own event history: DNS, certificates, money, sign-in and access, support, plans — all in one place.
- Who on our team opened your domain’s record or read its contacts is logged too, not just changes; a separate person reviews the log once a month.
- The team’s sign-in log in the account is kept for 30 days.
Locks and Registry Lock
- Transfer lock
- On by default for every domain; removing it requires typing the domain name to confirm.
- Contact lock
- On by default: while it’s on, the owner’s contacts can’t change. Removing it takes a fresh sign-in and a 72-hour pause; during the pause we don’t issue a transfer code, and any owner can cancel.
- DNSSEC
- We check the signature chain in monitoring; signing the zone right from the account is to be announced.
- Registry Lock (.ua)
- A lock at the registry level itself is to be announced: it depends on an answer from the
.uazone administrator. For other zones — wherever the registry itself supports it.
We notify all domain owners about a change of nameservers, contacts, locks, or a sign-in from a new device; critical notifications can’t be turned off.
Portfolio inventory
Add domains as a list, a CSV file, or a Cloudflare import — registration stays where it is, this isn’t a transfer. At launch, inventory and monitoring are free for the first 25 domains.
Certificates are visible across all domains, including ones we didn’t issue: someone else’s certificate issued for your domain shows up through Certificate Transparency logs — a signal of compromise or shadow IT, not just a list of your own certificates.
SLA
A formal SLA with compensation for corporate contracts isn’t defined yet — to be announced. General commitments during an incident are already public.
FAQ
Does the .ua registry support Registry Lock?
Still to be announced: it depends on an answer from the zone administrator, not only on us. Transfer lock and contact lock already work today for every domain.
Can an API key be scoped to a single domain?
Yes: when issuing a key you choose which domains it applies to. For rights that spend money, a domain list is mandatory — no “all, including future ones”.
How long is the action log kept?
The team’s sign-in log in the account is kept for 30 days. Each domain’s history shows everything that happened to it: DNS, certificates, money, sign-in and access, support, plans.
Is there an SLA with compensation?
There isn’t a formal SLA with compensation for corporate contracts yet — to be announced. General incident commitments are described on the status page.
What can an AI assistant connected through MCP see?
Read-only by default. Rights that spend money are granted as a separate checkbox with a limit; “ownership and irreversible” rights are never granted through OAuth.