Back to all guides

    Roles & Permissions

    Configure role-based access control for your team.

    Overview

    Role-based access control (RBAC) ensures users only have access to the features and data they need. Configure roles to match your organisation structure.

    Built-in Roles

    • Super Admin: Full platform access, can manage other admins
    • Admin: Full access except billing and admin management
    • Security Analyst: Manage findings, run scans, view reports
    • Compliance Manager: Manage policies, view compliance reports
    • Viewer: Read-only access to dashboards

    Step 1: Create Custom Role

    1. Navigate to Settings → Roles & Permissions
    2. Click "Create Custom Role"
    3. Name the role and add description
    4. Select a base role to start from (optional)

    Step 2: Configure Permissions

    Permission categories include:

    • Dashboard: View, customise
    • Security Findings: View, manage, dismiss
    • Policies: View, create, edit, delete
    • Reports: View, export, schedule
    • Integrations: View, configure, disconnect
    • Users: View, invite, manage
    • Settings: View, modify

    Step 3: Assign Scope

    1. Configure data scope (all data vs specific integrations)
    2. Limit access to specific security apps
    3. Restrict to certain policy categories
    4. Save the role configuration

    Step 4: Assign Users to Roles

    1. Go to Settings → Users
    2. Select user(s) to update
    3. Change their role assignment
    4. Changes take effect immediately

    Best Practices

    • Follow principle of least privilege
    • Review role assignments quarterly
    • Document custom role purposes
    • Use built-in roles when possible

    Need more help?

    Our support team is here to assist you with any questions.

    Contact Support