Users and Roles
Detectify uses role-based access control to determine what each person on your team can see and do.
Members are the users you add to your Detectify account. Roles are the permission levels you assign to those members to control what they can do within your team.
Roles
Detectify has three roles: Admin, Editor, and Viewer.
| Role | Summary |
|---|---|
| Admin | Full control over the team, including members, assets, and billing |
| Editor | Can manage assets and scan profiles, and read all security reports |
| Viewer | Read-only access to security reports |
Admin
Admins have full control over the team’s settings, including:
- Members — Invite members, change their roles, and remove them
- Assets — Add, remove, and configure the team’s assets, which can be both domains and IP ranges
- Surface Monitoring — Manage the team’s attack surface configuration
- Scan profiles — Create, edit, and delete scan profiles
- Billing — View and manage the team’s subscription and payment details
Admin is the only role with access to billing and member management, so every team needs at least one Admin.
Editor
Editors can manage what gets scanned and work with the results, but cannot change who has access to the team. An Editor can manage:
- Assets — Add, remove, and configure the team’s assets, both domains and IP ranges
- Scan profiles — Create, edit, and delete scan profiles
- Security reports — Access all security reports for the assets added to the team
Editors cannot manage members or access billing.
Viewer
Viewers have read-only access. A Viewer can only view security reports for the assets added to the team.
Use this role for people who need visibility into your security posture — such as stakeholders, auditors, or developers reviewing findings — without the ability to change any configuration.
Roles are set per team
Roles apply to the team they were assigned in, not to your whole account. If you belong to more than one team, you can hold a different role in each one — for example Admin in one team and Viewer in another. Use Switch team in the account menu to move between teams.
Managing members
Members and roles are managed on the Organization page. To get there, click your team name at the top of the left sidebar to open the account menu, then select Organization. The Members tab lists everyone in the current team along with their email, name, role, and last login.
Inviting members
- On the Members tab, click Invite members.
- Open the role dropdown and choose Admin role, Editor role, or Viewer role.
- Enter one or more email addresses in the Add email addresses field.
- Click Invite members.
Everyone included in a single invite receives the same role, so send one invite per role if you are adding people with different levels of access.
Invited people appear in the members list before they have signed in. Use the Expired / Pending filter to find invitations that are still outstanding or that have expired.
Changing a role
Find the person on the Members tab and open the dropdown in the Role column, then select their new role.
Removing members
Use the ⋮ menu in the Actions column to remove a member from the team. Removing someone revokes their access to the team’s assets, scan profiles, and security reports.
Best Practices
- Follow least privilege — Assign the lowest role that still lets someone do their job. Most people who just need to see findings should be Viewers.
- Limit Admins — Admin includes billing and member management, so keep the number of Admins small, but always have more than one so you are not locked out.
- Use teams to scope access — Separate teams for different business units, applications, or environments keep assets and reports visible only to the people who need them.
- Review membership regularly — Audit the members list periodically to remove people who no longer need access and clear out expired invitations.
- Use SSO — Centralize authentication through your identity provider for easier user lifecycle management.