This article explains what permissions depend on and links to the permissions article for each area of the platform.
Permissions can depend on:
Group Access
Some data can be shared either globally or based on the user’s access control group.
- Global: Shared configurations with all users.
- Group: Specific to a particular group.
Ownership
The following can be owned, which are configured based on user preferences:
- Alerts
- Collaboration Messages
- Company Notes
- Company Requests
- Finding Comments
- Folders
- User API Tokens
Find user permissions by area
Each article below lists what every role can and can't do.
- Access Control
- Account Preferences
- API
- Assessments
- Authentication
- Bitsight Badge
- Collaboration
- Company Relationships
- Company Requests
- Cyber Insurance
- Financial Quantification
- Folders
- Infrastructure
- Portfolio Risk Matrix
- Remediation & Mitigation: company notes, exposed credentials download, finding comments, issue tracking, work from home
- Self-Attested Compliance
- Settings
- Subscriptions
- Tiers
- Trust Management Hub & Vendor Risk Management Data
- User Management: activity log, assign roles, collaboration and subscription contacts, enable features, view user activity
- User Settings: Alerts, Notifications, & Email
Publish Date or Recent Edits
- September 30, 2026: Retitled article from "User Permissions" to "How user permissions work"
- April 7, 2025: Account preferences.
- January 3, 2025: Portfolio Risk Matrix permissions; Company Requests can be owned.
- November 25, 2024: Separated alerts, API, Bitsight Badge, company relationships, company requests, Financial Quantification, folders & infrastructure sections into their own articles; Combined account and SAML into authentication then separated into its own article; Combined 4th party & company relationships into its own article.
Comments
Please sign in to leave a comment.