Security
Roles and access
Every request passes one access check on the service. The dashboard and the command line show what the service answers; they decide nothing themselves.
The six roles
Section titled “The six roles”| Role | Servers and findings | Projects, settings | Adding servers |
|---|---|---|---|
| Owner | See and act | Manage | Yes |
| Admin | See and act | Manage | Yes |
| Member | See and act on findings | No | No |
| Viewer | See only | No | No |
| Billing | Hidden | No | No |
| Client | Hidden: status, incidents and reports only | No | No |
Access can be limited to some projects and environments, such as one client’s staging servers, and can end on a date.
The rules
Section titled “The rules”- Loaded fresh. A person’s role is read on every request, so a change applies on their next click.
- Hidden means not found. Asking for something you cannot see answers “not found”, the same as something that does not exist, so nobody can tell it is there.
- Teams never mix. Every database query is filtered by team, and by the projects you may see. A test proves that only these files reach the database.
- Nobody raises their own access. Only owners make owners and admins, or change an owner. A team always keeps at least one owner.
- Tokens do one thing. A server token can only send that server’s results. A person’s session can never send results.
- A fresh code for server tokens. Adding a server asks for a new code from your authenticator app.