Roles and access
Access in ReconForge is controlled by your role and your organization. You never pass a role or an organization by hand. Both come from your account.
Roles are hierarchical. A higher role includes everything a lower one can do.
| Role | Can do |
|---|---|
| Viewer | Read projects, runs, and findings. No changes. |
| Analyst | Everything a viewer can, plus launch runs, triage findings, and use the assistant. |
| Admin | Everything an analyst can, plus define scope (projects and targets), manage users, and configure the organization. |
A separate platform operator role exists for running the platform itself: provisioning organizations, setting global configuration, and licensing. It is a control-plane role that does not have access to any organization’s assessment data. On the managed cloud this role is us. On self-hosted it is your operator. See Managing organizations.
Organizations
Section titled “Organizations”Your data is scoped to your organization. You only ever see your own organization’s projects, runs, and findings, and anything outside it is simply not visible. This is how the platform keeps tenants isolated.
Single sign-on
Section titled “Single sign-on”When your organization uses single sign-on, roles come from your identity provider. An administrator maps groups in your provider to ReconForge roles, and each person’s role is set from their group membership at sign-in. See Single sign-on.
- Users and roles: add people and set their roles.
- Single sign-on: connect your identity provider.