Skip to content

FAQ

What are the platform roles and what permissions does each role have?

Section titled “What are the platform roles and what permissions does each role have?”

Currently these permissions are divided into 7 hardcoded roles:

  • Admins: Full access across all modules, including managing users, configuring integrations, and adjusting organization settings.
  • Editors: Can create, modify, and delete content like risks, incidents, threats, and documents, and can perform actions like approving threat proposals, but cannot change organization-level settings, manage other users, or configure integrations.
  • Viewers: Read-only access across the entire platform. Viewers can follow risks and incidents. Can generate governance reports.
  • Risk Viewer: Read-only access to all modules except the incident module. Can follow risks.
  • Risk Editor: Can create, modify, and delete resources excluding the incident module. Can suggest and approve Threat Profile changes.
  • Incident Viewer: Read-only access to all modules except the risk module. Can follow incidents.
  • Incident Editor: Can create, modify, and delete resources excluding the risk module. Can suggest Threat Profile changes and deny proposals, but cannot approve them.

User roles can be assigned in two ways:

  1. When a member is invited: the invitation includes their email address and the roles they will hold when they join.
  2. By changing the roles on an existing account, upgrading or downgrading what the member can do in the platform.

Not yet. Every role available today is one of the seven built-in roles, though you can assign a member several of them and their permissions combine. Custom roles — letting your organization define its own permission sets tailored to specific workflows — are planned as a near-term addition.

Is there a limitation regarding the number of administrators a tenant can have?

Section titled “Is there a limitation regarding the number of administrators a tenant can have?”

A tenant can have many Admins; at a minimum it needs one.

A user cannot modify their own permissions or change their own role. That change must be made by another Admin.

Can Risk Editors and Incident Editors adjust and approve the Threat Profile?

Section titled “Can Risk Editors and Incident Editors adjust and approve the Threat Profile?”

Both the Risk and Incident Editors can edit threats and save to make suggestions. Of these two roles, only the Risk Editor can approve changes to a Threat Profile. This is to ensure any adjustments to the Threat Profile are approved accordingly.

Can Risk Viewers/Editors and Incident Viewers/Editors generate governance reports?

Section titled “Can Risk Viewers/Editors and Incident Viewers/Editors generate governance reports?”

No, these roles currently do not have the permissions to generate governance reports, as the reports contain access to data that they may not have permission to view. A user needs to be a platform Admin, Editor, or Viewer to generate governance reports.