User roles

Roles control what members of your organization can see and do in XBOW. Roles are set by users with the organization administrator role.

You can see how these roles map to the steps of an assessment in the Console quickstart.

Roles

Viewer

Read-only access to the organization. Viewers can see assets, domains, assessments, findings, and reports, but cannot make any changes or run tests.

Monitor

All Viewer permissions, plus the ability to pause a running assessment in an emergency. Monitors cannot resume assessments.

Uploader

All Viewer permissions, plus the ability to upload resources such as new file versions.

Developer

All Uploader and Monitor permissions, plus the ability to run assessments on assets that are in “Preflight successful” status. Developers can start, stop, and resume these assessments, update findings, manage asset profiles, and update existing assets. They cannot add assets or set up credentials themselves.

Existing Asset Administrator

All Developer permissions, plus the ability to manage members, attack credits, and the configuration of the organization.

Administrator

All Existing Asset Administrator permissions, plus the ability to create assets, manage the organization allowlist, and view the audit log. Administrators can also manage personal access tokens and webhook subscriptions for use with the XBOW API.

Permissions by role

PermissionViewerMonitorUploaderDeveloperExisting Asset AdminAdministrator
Sign in and manage sessionsYesYesYesYesYesYes
View organization, assets, domains, assessments, findings, and reportsYesYesYesYesYesYes
Pause a running assessmentNoYesNoYesYesYes
Upload resourcesNoNoYesYesYesYes
Update findings, including tracking external workNoNoNoYesYesYes
Manage asset profilesNoNoNoYesYesYes
Manage resourcesNoNoNoYesYesYes
Manage assessments (start, stop, pause, resume)NoNoNoYesYesYes
Update existing assetsNoNoNoYesYesYes
Manage domainsNoNoNoNoYesYes
Manage asset credentialsNoNoNoNoYesYes
Manage attack creditsNoNoNoNoYesYes
Manage organization members and settingsNoNoNoNoYesYes
Create assetsNoNoNoNoNoYes
Manage personal access tokensNoNoNoNoNoYes
Manage webhook subscriptionsNoNoNoNoNoYes
Manage organization allowlistNoNoNoNoNoYes
View audit logNoNoNoNoNoYes

Was this helpful?