Members & Roles

Understand team roles (Owner, Admin, Member) and their permissions.

Each team member has a role that determines what they can do within the team.

Roles

Owner

The team creator is automatically assigned the Owner role. Owners have full control over the team:

  • Manage all products, releases, SBOMs, and VEX documents
  • Approve and publish VEX documents
  • Invite and remove team members
  • Change member roles
  • Manage billing and subscription
  • Access and export audit logs
  • Delete the team account

Admin

Admins have elevated permissions for day-to-day management:

  • Manage all products, releases, SBOMs, and VEX documents
  • Approve and publish VEX documents
  • Invite team members
  • Access and export audit logs
  • Cannot manage billing or delete the team

Member

Members can perform most vulnerability management tasks:

  • Create and manage products, releases, and SBOMs
  • Triage vulnerabilities and set dispositions
  • Generate and submit VEX documents for review
  • View audit logs
  • Cannot approve or publish VEX documents
  • Cannot manage team members or billing

Permissions summary

ActionOwnerAdminMember
Manage products & releasesYesYesYes
Upload & manage SBOMsYesYesYes
Triage vulnerabilitiesYesYesYes
Generate VEX documentsYesYesYes
Submit VEX for approvalYesYesYes
Approve/reject VEXYesYesNo
Publish VEXYesYesNo
Invite membersYesYesNo
Remove membersYesNoNo
Change member rolesYesNoNo
Manage billingYesNoNo
Export audit logsYesYesYes

Changing a member's role

  1. Navigate to Members in the sidebar
  2. Find the member in the list
  3. Click the role dropdown next to their name
  4. Select the new role

Only Owners can change member roles.