What roles are available?
For users of the Cloud, Pro, Enterprise, and Vanguard plans, you can choose between 'Admin', 'Manage', 'Scan user', and 'Read-only'.
What's the difference?
Admin users have full access to the portal and account settings. They're the only role that can manage users, integrations, billing, and API access tokens, create or delete tags, and run AI penetration tests.
The Manage role is for people who look after targets day to day. They can add, edit, and delete targets, run scans, and snooze issues, but they can't see account settings such as users, integrations, and billing.
The Scan user role is for people who run and schedule scans. They can view targets and issues, add authentications and API schemas, and start, schedule, and cancel scans, but they can't add, edit, or delete targets, snooze issues, or see account settings.
The read-only user has very limited access and is designed for those who just want to see the portal, rather than take any action. This might be a stakeholder or someone new to the team who needs to be onboarded.
Capability | Admin | Manage | Scan user | Read-only |
Add targets | ✅ | ✅* | ❌ | ❌ |
Add authentications | ✅ | ✅ | ✅ | ❌ |
Add API schemas | ✅ | ✅ | ✅ | ❌ |
Edit targets | ✅ | ✅ | ❌ | ❌ |
Delete targets | ✅ | ✅* | ❌ | ❌ |
Export targets | ✅ | ✅ | ✅ | ✅ |
Run Issue Triage & Investigation | ✅ | ✅ | ❌ | ❌ |
Access to AI Penetration Tests | ✅ | ❌ | ❌ | ❌ |
Start one-off scan | ✅ | ✅ | ✅ | ❌ |
Start/edit/delete scheduled scan | ✅ | ✅ | ✅ | ❌ |
Start remediation scan | ✅ | ✅ | ✅ | ❌ |
Manage scan priorities | ✅ | ✅ | ✅ | ❌ |
Cancel scans | ✅ | ✅ | ✅ | ❌ |
Edit scan settings (priority, ETS, network scan, region) | ✅ | ✅** | ✅** | ❌ |
View issues | ✅ | ✅ | ✅ | ✅ |
Snooze/unsnooze | ✅ | ✅* | ❌ | ❌ |
Download reports | ✅ | ✅ | ✅ | ✅ |
Export checks | ✅ | ✅ | ✅ | ❌ |
Add/change/delete a user | ✅ | ❌ | ❌ | ❌ |
Add/edit/delete an integration | ✅ | ❌ | ❌ | ❌ |
Purchase licenses | ✅ | ❌ | ❌ | ❌ |
Access billing/download invoices/cancel plan | ✅ | ❌ | ❌ | ❌ |
Close user account | ✅ | ✅ | ✅ | ✅ |
Create API access tokens | ✅ | ❌ | ❌ | ❌ |
* Users restricted to specific tags can only add targets with their own tags. To delete a target, or snooze and unsnooze its issues, they need access to every tag on that target.
** Only available to users who aren't restricted to specific tags.
How do I assign a role?
When adding a new user to the account, click your profile > Users > Add a user:
Once you've added their name and email address, select Admin, Manage, Scan user, or Read-only for the Role.
If you choose Manage, Scan user, or Read-only as the role, you also have the option to restrict access to specific tags (if you're subscribed to Enterprise or Vanguard).
Once that's all done, hit
Add user.
Can I change an existing user's role?
Absolutely, so long as you're an Admin; just head to your profile avatar > Settings > Users > click ... > Edit:
You can then adjust their role and their permissions (if the user is not an admin and you're currently subscribed to Enterprise/Vanguard):
The change is effective immediately.
⚠️ Important: Once a user has been changed to 'Manage', 'Scan user', or 'Read-only', the only way to reverse it is to ask an Admin on the account to update it.
FAQs
Question | What happens |
Can a restricted Manage user see other teams' targets? | No. They only see targets tagged with the tags they're assigned. |
What happens when a Manager deletes a target? | It's removed from view but can be recovered. A Manage user can restore it if they have access to every tag on it, and an Admin can always restore it. |
A Manager was told to contact their admin when adding a target - why? | The target already exists in a part of the account they don't have access to. For privacy, we don't reveal targets outside a user's access; an admin can grant it. |
Can Managers change tags? | They can tag and untag their own targets. Creating or deleting tags, and assigning users to tags, stays with admins. |
Can Managers snooze issues? | Yes, on their own targets. For targets shared with another team, snoozing stays with admins so one team can't hide issues from another. |
Do Managers get separate scan credits? | No. AI credits are shared across the whole account. |
Can Managers run AI pentests? | No, that's Admin-only. They can run Issue Triage & Investigation. |



