Docs
Administration

Users and access

Add people, choose their role per project, approve people waiting to join, work with guests from other organisations, and remove or restore an account.

People are managed under Settings → Organisation Management → User Management. Only an organisation admin sees it. The list is split into Active, Pending and Deleted, with Add User above it.

Roles are per project

A role is given to a person for one project, and there are three:

RoleWhat it allows
ReaderRead the project's data, but not its settings or members.
ContributorManage the project's data (assets, findings, risks, compliance), but not its settings or members.
AdminManage the project, its settings and its members. Shown as Project Admin.

Admin on your organisation's main project is different: it is shown as Super Admin and covers every project, every user and every organisation setting. Contributors can't manage users, integrations, API keys or organisation settings, whichever project they're in.

Remove from project takes away someone's roles on one project and leaves their account and other projects alone. The platform won't let you remove or demote the last organisation admin, or remove yourself.

Add someone

Choose Add User, enter their name and email address, pick a role, and optionally add a message. Everyone you add is emailed: a new account gets an activation link, and an existing one is told it now has access.

Someone with an address at your organisation's domain becomes a member. Anyone else joins as a guest, with the role you chose, and their account stays with their own organisation. Invite people at their work address.

Approve people waiting to join

Someone who asks to join your organisation without an invitation from one of your admins waits for approval. They have no access and use no seat until an admin approves them.

Open the Pending tab and choose Approve or Decline, one at a time or several together. An approved person becomes a member and uses a seat. A declined person isn't admitted; their own account and any access they hold elsewhere are unaffected.

Guests from other organisations

A guest is listed with Granted Access. You choose their role in each project, just as for a member, but their profile is managed by their own organisation.

To withdraw a guest entirely, use Remove from organisation. Their own account is unaffected. Removing their last project role has the same effect.

Share one project

To bring someone into a single project, open the ⋯ menu on that project in the sidebar and choose Share Project. It needs the Admin role on that project, and works like Add User: the same roles and the same email. It's the way to give a team a narrow slice of your estate, since project membership is what decides which assets someone can see.

Remove, restore and permanently remove

  • Remove user takes a member out of the organisation and moves them to the Deleted tab. It needs a reason, and you can't remove your own account.
  • Restore User, on the Deleted tab, makes them active again. Adding a removed person's address again offers to restore them instead.
  • Remove Permanently deletes the account itself: its memberships, roles, API keys and sign-in. You confirm it by typing their email address. It can't be undone from the app, their past entries in the audit log are kept, and the address can be invited again afterwards.

Seat limits

Your plan sets how many members your organisation can have; see pricing. The limit is checked when you add, restore or approve a member, and an Upgrade plan button appears if you have reached it.

On this page