Roles and permissions
What owners, admins, analysts and viewers can each do.
Every member of an organization has one of four roles. The same roles apply to API keys: a key acts with the permissions of the role it was created with.
| Permission | Owner | Admin | Analyst | Viewer |
|---|---|---|---|---|
| View assessments, findings, evidence, reports | ✓ | ✓ | ✓ | ✓ |
| Create and authorise assessments | ✓ | ✓ | ✓ | |
| Start, retry and cancel assessments | ✓ | ✓ | ✓ | |
| Triage findings (assign, comment, status, verify) | ✓ | ✓ | ✓ | |
| Manage monitoring subscriptions | ✓ | ✓ | ✓ | |
| Work on questionnaires and second opinions | ✓ | ✓ | ✓ | |
| Connect Microsoft 365 / AWS | ✓ | ✓ | ||
| Manage billing and subscription | ✓ | ✓ | ||
| Create, rotate and revoke API keys | ✓ | ✓ | ||
| Change organization name and logo | ✓ | ✓ | ||
| Receive the Executive Brief by email | ✓ | ✓ |
Owner vs. admin
Owners and admins have the same permissions inside the organization. The difference is ownership:
- when you delete your account, any organization where you are the only owner is deleted with it. Organizations with another owner are kept;
- a partner account always keeps at least one owner.
Least privilege
Give day-to-day users the analyst role, and viewer to people who only need to read reports, such as auditors or executives. Keep owner/admin for the few people who manage billing, connectors and keys.