Team & Roles
HOW ROLES WORK
Not everyone on a security team needs the same keys. Four roles cover how that work actually divides.
- ADMIN
- full control of the workspace: manages users, settings, and clients. Usually the security lead who owns the engagement.
- CLIENT ADMIN
- built for consultancies and MSSPs running more than one client through the same workspace. Scoped to only the clients assigned to them — enforced at the API, not just hidden in the interface.
- MEMBER
- the working analyst seat: creates and edits assets, threats, and controls, and runs the assessments. The seat that does the modeling.
- VIEWER
- read-only by enforcement. Sees everything, generates reports, can't change a field. Call the API directly instead of clicking a button, and a viewer still gets a 403.