Skip to content

Roles and access

Access in ReconForge is controlled by your role and your organization. You never pass a role or an organization by hand. Both come from your account.

Roles are hierarchical. A higher role includes everything a lower one can do.

Role Can do
Viewer Read projects, runs, and findings. No changes.
Analyst Everything a viewer can, plus launch runs, triage findings, and use the assistant.
Admin Everything an analyst can, plus define scope (projects and targets), manage users, and configure the organization.

A separate platform operator role exists for running the platform itself: provisioning organizations, setting global configuration, and licensing. It is a control-plane role that does not have access to any organization’s assessment data. On the managed cloud this role is us. On self-hosted it is your operator. See Managing organizations.

Your data is scoped to your organization. You only ever see your own organization’s projects, runs, and findings, and anything outside it is simply not visible. This is how the platform keeps tenants isolated.

When your organization uses single sign-on, roles come from your identity provider. An administrator maps groups in your provider to ReconForge roles, and each person’s role is set from their group membership at sign-in. See Single sign-on.