Roles and permissions
| Role | Typical person | Highlights |
|---|---|---|
| Owner | Founder / CTO | Everything, including billing and organisation deletion |
| Admin | Platform / IT admin | Configuration, integrations, users, SSO, API tokens, webhooks |
| Security | Product security engineer | Products, SBOMs, vulnerability triage, incidents, CRA cases, evidence, API tokens |
| Compliance | Compliance / legal lead | Requirements, evidence, reports, CRA cases, auditor access, legal hold, policies |
| Engineer | Developer | Assigned products, SBOM upload, triage, tasks |
| Auditor | Internal audit | Read-only across operational data and the audit log |
| External advisor | Consultant with limited scope | Custom permission set |
Two additional access modes exist: support access (Vellaci operators, granted by you, time-bound, logged) and auditor mode (external auditors, time-limited, scoped, read-only, logged). Partner consultants receive a normal membership with the maximum role you allow.
High-risk operations (changing an awareness timestamp, reversing a reportability decision, deleting evidence, amending a submission, rotating secrets, changing owner/admin roles) require an MFA-verified session and, when enabled, a second approver.
Last updated . This page describes the current release.