Roles and permissions
What a Reader, Contributor and Admin can do in each part of CISO360AI, how Admin on the main project applies across the organisation, and how guests fit in.
- Who can do this: Reader · Contributor · Admin
- In the app: Settings › Organisation Management › User Management
- 5 min
Reader, Contributor and Admin
Each person has a role on each project they can reach.
| Role | What it adds over the role below |
|---|---|
| Reader | Views the project's work: assets, scans and domains, findings, risks, actions, policies, engagements and reports, and compliance assessments and evidence. Opens details and chats with AI Sidekick. |
| Contributor | Creates, edits and deletes that work. Approves and rejects proposals. |
| Admin | Changes settings, as listed below. |
What needs Admin
Admin on any project:
- Enable, disable, delete or import a compliance framework.
- Save Preferences and document variables, and turn on a scan module.
- Approve a proposal that imports a framework or changes preferences.
- Reveal a leaked credential in Exposure.
- Share the project with someone, choosing their role on it (Share Project).
What needs Admin on the main project
Every organisation has a main project. Admin on it is shown as Super Admin in the app, and Admin on any other project as Project Admin. These need Admin on the main project:
- Resolve or reopen identity exposures, and act on configuration checks.
- Connect or sync an integration.
- Create, rename or delete a project.
- View the Configuration dashboard.
- Tailor an AI Sidekick persona.
- Invite and manage people, change organisation settings and notifications, manage everyone's API keys, and choose what agent keys may be given, all in Organisation Management.
- Read the Audit Log and manage Subscriptions.
- Set document branding for exports.
Plan limits apply on top of roles. Some actions depend on your plan; see pricing.
Guests
A guest has a role on each project shared with them. See Users and access.
AI agents and API keys
An agent key acts with its owner's role and the capabilities its owner chose from those an administrator enabled. See API keys and what an agent can do.
Did this answer your question?
Key terms
The CISO360AI terms that are easy to confuse, such as finding, vulnerability and observation, or assessment and engagement, with a one-line definition of each.
API and MCP reference
Where to find the OpenAPI schema, the interactive API explorer and the MCP tool list for the CISO360AI REST API and MCP server, and how to authenticate with an API key.