Skip to content

Members and roles

Role Can
Viewer Read everything: runs, findings, reports, usage
Analyst Viewer, plus start runs, change finding statuses, add and verify sites
Admin Analyst, plus manage members, API keys, branding and settings
Owner Admin, plus change roles and billing

Settings → Members → enter an email and a role. The invite is attached the moment that address signs in — with a password or through single sign-on — so there is nothing for them to accept.

Workspaces on the Enterprise plan can connect an OIDC provider (WorkOS AuthKit, Okta, Entra ID, Auth0). Sign-in then happens through the provider; local passwords are not needed.

Admins create keys under Settings → API keys. A key acts as its workspace with analyst or viewer rights depending on its scopes, is shown once, and can be revoked at any time. Send it as Authorization: Bearer ca_….