Members and roles
| Role | Can |
|---|---|
| Viewer | Read everything: runs, findings, reports, usage |
| Analyst | Viewer, plus start runs, change finding statuses, add and verify sites |
| Admin | Analyst, plus manage members, API keys, branding and settings |
| Owner | Admin, plus change roles and billing |
Inviting someone
Section titled “Inviting someone”Settings → Members → enter an email and a role. The invite is attached the moment that address signs in — with a password or through single sign-on — so there is nothing for them to accept.
Single sign-on
Section titled “Single sign-on”Workspaces on the Enterprise plan can connect an OIDC provider (WorkOS AuthKit, Okta, Entra ID, Auth0). Sign-in then happens through the provider; local passwords are not needed.
API keys
Section titled “API keys”Admins create keys under Settings → API keys. A key acts as its workspace with analyst or viewer
rights depending on its scopes, is shown once, and can be revoked at any time. Send it as
Authorization: Bearer ca_….