Team & roles (RBAC)
Invite people and control what they can see and do with roles.
Overview
The Team area is where you manage who has access and what they can do. SecNxt uses role-based access control so people get exactly the permissions they need — no more.
Roles are surfaced as three friendly levels — Admin, Analyst and Viewer — backed by a more granular permission engine.
How it works
Permissions are checked on every sensitive action (inviting members, managing billing, reading the audit log, etc.).
Roles are assigned per workspace, so someone can be an Admin in one engagement and a Viewer in another.
How to use it
- 1Open Team from the sidebar.
- 2Invite a person by email and choose their role.
- 3Adjust roles later as responsibilities change.
- 4Remove access when someone leaves the engagement.
When to use it
- Giving clients read-only (Viewer) access to their own findings.
- Letting analysts work findings without granting billing control.
Tips & best practices
- Grant the least privilege that lets someone do their job.
- Admins can manage members and settings — reserve that role carefully.
FAQ
- What's the difference between the roles?
- Admins manage the workspace and people; Analysts do security work; Viewers can see results but not change things.
Related guides
Invitations
Bring new people in with a secure, role-scoped invite link.
Workspaces
Isolated spaces — one per client or engagement — that keep work separate.
Organisation
The top-level account that owns your workspaces, members and plan.
Sessions & devices
See where you're signed in and sign out devices you don't recognise.