A user's permissions in Bitsight depend on four factors: group access, ownership, the user's role, and the user's Trust Management Hub and Vendor Risk Management role. This article defines group access and ownership and lists the articles that give permissions by role for each area of the platform.
Applies to: All Bitsight platform users.
What determines what a user can do in Bitsight?
- Group access
Whether a configuration applies to all users or to one access control group. Find more details in the Group access section of this article.
- Ownership
Whether a user can change an item the user created. Find more details in the Ownership section in this article.
- User role
Controls what actions the user can do.
- Trust Management Hub and Vendor Risk Management role
Control what actions the user can do in VRM and TMH.
Learn more at the Vendor Risk Management and Trust Management Hub user roles article.
What is group access?
Some data can be shared either globally or based on the user’s access control group.
- Global: Shared configurations with all users.
- Group: Specific to a particular group.
What is ownership?
Ownership means a user created an item and can change it. For several actions, a user can edit or delete an item only if the user owns it. Users configure ownership through their user preferences.
Users can own the following items:
- Alerts
- Collaboration Messages
- Company Notes
- Company Requests
- Finding Comments
- Folders
- User API Tokens
Find user permissions by area
Each article below lists what every role can and cannot do in one area, by role and by action.
- Access Control
- Account Preferences
- API
- Assessments
- Authentication
- Bitsight Badge
- Collaboration
- Company Relationships
- Company Requests
- Cyber Insurance
- Financial Quantification
- Folders
- Infrastructure
- Portfolio Risk Matrix
- Remediation & Mitigation: company notes, exposed credentials download, finding comments, issue tracking, work from home
- Self-Attested Compliance
- Settings
- Subscriptions
- Tiers
- Trust Management Hub & Vendor Risk Management Data
- User Management: activity log, assign roles, collaboration and subscription contacts, enable features, view user activity
- User Settings: Alerts, Notifications, & Email
- September 30, 2026: Retitled article from "User Permissions" to "How user permissions work"
- April 7, 2025: Account preferences.
- January 3, 2025: Portfolio Risk Matrix permissions; Company Requests can be owned.
- November 25, 2024: Separated alerts, API, Bitsight Badge, company relationships, company requests, Financial Quantification, folders & infrastructure sections into their own articles; Combined account and SAML into authentication then separated into its own article; Combined 4th party & company relationships into its own article.
Comments
Please sign in to leave a comment.