Managing team members

Created by Kurt Chrisford, Modified on Fri, 25 Sep at 2:57 PM by Kurt Chrisford

You can invite as many people as you need and give each one a role that matches what they do. Only Owners can invite, change or remove team members.

Roles

RoleWhat they can do
OwnerEverything, including billing and managing the team.
ManagerEverything except billing and managing the team: assets, scans, settings and fixing findings.
AnalystSee everything and work on findings: change statuses, assign and verify fixes.
MemberRead-only access to your data. This is the default for new invitations.
ViewerRead-only access, intended for people outside your organisation, such as auditors.
BillingBilling and subscription management only. They can't see your security data.

Give each person the lowest role that lets them do their job. You can change it later.

Invite someone

  1. In the sidebar, go to Team and select Team members.
  2. Select Invite team member.
  3. Enter their Email address and choose a Role.
  4. Select Send invitation.

They'll get an email with a link to join. Invitations expire after 7 days. Pending invitations are listed on the Team members page, where you can change the role or cancel the invitation.

If they already have an account

If the person already uses Cyber Perimeter with another organisation, the invitation adds your organisation to their existing account. They sign in, then select Join. They keep access to their other organisations and can switch between them from their account menu.

Remove someone

On the Team members page, select Remove next to their name and confirm. They lose access immediately and are signed out everywhere. You can't remove yourself or your organisation's last Owner.

Signing in securely

Everyone on your team signs in with two-factor authentication. If your organisation uses single sign-on, your identity provider handles sign-in instead.

Single sign-on and automatic provisioning

Single sign-on (SSO) and SCIM provisioning are included on every plan, at no extra cost. We treat them as basic security, like two-factor authentication, not an enterprise add-on.

To connect your identity provider, such as Microsoft Entra ID, Okta or Google Workspace, go to Settings and open Single sign-on. We support:

  • SAML single sign-on, with accounts created automatically the first time someone signs in
  • SCIM provisioning, so people are added and removed as they join and leave your organisation

When your identity provider deactivates someone, their access ends immediately. Only Owners can change these settings.

See who changed what

Every team change, and every change to findings, is recorded. To see it, go to Team and select Audit trail. Owners and Managers can view it.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article