Users and roles
Planned platform capability
A user belongs to a workspace and receives a role that controls what they can change or review. The first role model keeps this distinction small and explicit.
Administrator
Section titled “Administrator”Administrators manage the workspace. They can:
- connect and configure repository sources;
- choose which repositories receive protection;
- manage product and enforcement settings;
- invite users and assign roles;
- manage community access; and
- review findings and operational evidence.
Because administrator actions can change protection or access for other people, the application should explain their effect before applying them.
Viewer
Section titled “Viewer”Viewers review the information available to them. They can:
- see the workspace and products they have been granted access to;
- inspect findings, scan results, and evidence; and
- use views and searches that do not change configuration.
Viewers cannot change workspace settings, protection policy, integrations, billing, or membership.
Community access
Section titled “Community access”A workspace can grant a viewer access to specific communities. Community grants are explicit, so becoming a workspace viewer does not automatically expose every community.
Administrators retain workspace-wide access. Viewers see only the communities granted to them.