User roles
Roles control what members of your organization can see and do in XBOW. Roles are set by users with the organization administrator role.
Roles
Locked
Ability to authenticate and request a quote for a new assessment only.
Lightspeed users are automatically assigned this role when their assessment access expires. Role not available for Enterprise users.
Viewer
Read-only access to the organization. Viewers can see assets, domains, assessments, findings, and reports, but cannot make any changes or run tests.
Monitor
All Viewer permissions, plus the ability to pause a running assessment in an emergency. Monitors cannot resume assessments.
Uploader
All Viewer permissions, plus the ability to upload resources such as new file versions.
Developer
All Uploader and Monitor permissions, plus the ability to start, stop, and resume assessments, update findings, manage asset profiles, and update existing assets.
Existing Asset Administrator
All Developer permissions, plus the ability to manage members, attack credits, and the configuration of the organization.
Administrator
All Existing Asset Administrator permissions, plus the ability to create and delete assets, manage the organization allowlist, and view the audit log. Administrators can also manage personal access tokens and webhook subscriptions for use with the XBOW API.
Permissions by role
| Permission | Locked | Viewer | Monitor | Uploader | Developer | Existing Asset Admin | Administrator |
|---|---|---|---|---|---|---|---|
| Sign in and manage sessions | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| View organization, assets, domains, assessments, findings, and reports | No | Yes | Yes | Yes | Yes | Yes | Yes |
| Pause a running assessment | No | No | Yes | No | Yes | Yes | Yes |
| Upload resources | No | No | No | Yes | Yes | Yes | Yes |
| Update findings | No | No | No | No | Yes | Yes | Yes |
| Manage asset profiles | No | No | No | No | Yes | Yes | Yes |
| Manage resources | No | No | No | No | Yes | Yes | Yes |
| Manage assessments (start, stop, pause, resume) | No | No | No | No | Yes | Yes | Yes |
| Update existing assets | No | No | No | No | Yes | Yes | Yes |
| Manage domains | No | No | No | No | No | Yes | Yes |
| Manage asset credentials | No | No | No | No | No | Yes | Yes |
| Manage attack credits | No | No | No | No | No | Yes | Yes |
| Manage organization members and settings | No | No | No | No | No | Yes | Yes |
| Create and delete assets | No | No | No | No | No | No | Yes |
| Manage personal access tokens | No | No | No | No | No | No | Yes |
| Manage webhook subscriptions | No | No | No | No | No | No | Yes |
| Manage organization allowlist | No | No | No | No | No | No | Yes |
| View audit log | No | No | No | No | No | No | Yes |