Roles and permissions

RoleTypical personHighlights
OwnerFounder / CTOEverything, including billing and organisation deletion
AdminPlatform / IT adminConfiguration, integrations, users, SSO, API tokens, webhooks
SecurityProduct security engineerProducts, SBOMs, vulnerability triage, incidents, CRA cases, evidence, API tokens
ComplianceCompliance / legal leadRequirements, evidence, reports, CRA cases, auditor access, legal hold, policies
EngineerDeveloperAssigned products, SBOM upload, triage, tasks
AuditorInternal auditRead-only across operational data and the audit log
External advisorConsultant with limited scopeCustom permission set

Two additional access modes exist: support access (Vellaci operators, granted by you, time-bound, logged) and auditor mode (external auditors, time-limited, scoped, read-only, logged). Partner consultants receive a normal membership with the maximum role you allow.

High-risk operations (changing an awareness timestamp, reversing a reportability decision, deleting evidence, amending a submission, rotating secrets, changing owner/admin roles) require an MFA-verified session and, when enabled, a second approver.

Last updated . This page describes the current release.