Permissions overview: how roles, groups and ownership affect access

A user's permissions in Bitsight depend on four factors: group access, ownership, the user's role, and the user's Trust Management Hub and Vendor Risk Management role. This article defines group access and ownership and lists the articles that give permissions by role for each area of the platform.

Applies to: All Bitsight platform users.

What determines what a user can do in Bitsight?

Group access

Whether a configuration applies to all users or to one access control group. Find more details in the Group access section of this article.
 

Ownership

Whether a user can change an item the user created. Find more details in the Ownership section in this article.
 

User role

Controls what actions the user can do.

Learn more at the User Roles article.
 

Trust Management Hub and Vendor Risk Management role

Control what actions the user can do in VRM and TMH.

Learn more at the Vendor Risk Management and Trust Management Hub user roles article.
 

What is group access?

Some data can be shared either globally or based on the user’s access control group.

  • Global: Shared configurations with all users.
  • Group: Specific to a particular group.

What is ownership?

Ownership means a user created an item and can change it. For several actions, a user can edit or delete an item only if the user owns it. Users configure ownership through their user preferences.

Users can own the following items:

Find user permissions by area

Each article below lists what every role can and cannot do in one area, by role and by action.

Publish Date or Recent Edits
  • September 30, 2026: Retitled article from "User Permissions" to "How user permissions work"
  • April 7, 2025: Account preferences.
  • January 3, 2025: Portfolio Risk Matrix permissions; Company Requests can be owned.
  • November 25, 2024: Separated alerts, API, Bitsight Badge, company relationships, company requests, Financial Quantification, folders & infrastructure sections into their own articles; Combined account and SAML into authentication then separated into its own article; Combined 4th party & company relationships into its own article.
Was this article helpful?
7 out of 8 found this helpful

Comments

0 comments

Please sign in to leave a comment.