Back to all guides
Roles & Permissions
Configure role-based access control for your team.
Overview
Role-based access control (RBAC) ensures users only have access to the features and data they need. Configure roles to match your organisation structure.
Built-in Roles
- Super Admin: Full platform access, can manage other admins
- Admin: Full access except billing and admin management
- Security Analyst: Manage findings, run scans, view reports
- Compliance Manager: Manage policies, view compliance reports
- Viewer: Read-only access to dashboards
Step 1: Create Custom Role
- Navigate to Settings → Roles & Permissions
- Click "Create Custom Role"
- Name the role and add description
- Select a base role to start from (optional)
Step 2: Configure Permissions
Permission categories include:
- Dashboard: View, customise
- Security Findings: View, manage, dismiss
- Policies: View, create, edit, delete
- Reports: View, export, schedule
- Integrations: View, configure, disconnect
- Users: View, invite, manage
- Settings: View, modify
Step 3: Assign Scope
- Configure data scope (all data vs specific integrations)
- Limit access to specific security apps
- Restrict to certain policy categories
- Save the role configuration
Step 4: Assign Users to Roles
- Go to Settings → Users
- Select user(s) to update
- Change their role assignment
- Changes take effect immediately
Best Practices
- Follow principle of least privilege
- Review role assignments quarterly
- Document custom role purposes
- Use built-in roles when possible