Users are managed on the Users tab of the Access Control page. To open it, select Settings, then Access Control, then the Users tab. A user's role determines who can approve new users, assign roles and contacts, enable features, and view user activity. This article lists the user management permissions for each role and for each action.
Roles referenced on this page: Users with the Admin, Group Admin, Portfolio Manager, Operations, Internal Business User, User, or View Only role.
What can my role do?
Use this section to find everything a specific role can and can't do with user management. For a breakdown by action instead, see By action below.
- Can access the activity log.
- Can approve newly registered Bitsight Vendor Risk Management users.
- Can assign any role to any user.
- Can assign a collaboration contact and a subscription contact.
- Can be a collaboration contact and a subscription contact.
- Can enable company request notifications.
- Can enable features for a user.
- Can enable portfolio-level features, such as Dark Web.
- Can generate a Platform Usage report.
- Cannot access the activity log.
- Can assign users in their group the User, Portfolio Manager, or Group Admin role.
- Can assign a collaboration contact and a subscription contact from the users in their group.
- Can be a collaboration contact.
- Can be a subscription contact on behalf of the group.
- Can enable company request notifications if they own them.
- Can enable features for users in their group.
- Cannot enable portfolio-level features.
- Can generate a Platform Usage report.
- Approving new Bitsight Vendor Risk Management users does not apply to this role.
- Cannot access the activity log, assign roles, assign contacts, or enable features.
- Cannot enable portfolio-level features.
- Can be a collaboration contact.
- Can be a subscription contact on behalf of the group.
- Can enable company request notifications if they own them.
- Can generate a Platform Usage report.
- Approving new Bitsight Vendor Risk Management users does not apply to this role.
- Cannot approve new Bitsight Vendor Risk Management users.
- Cannot assign roles.
- Cannot enable features for a user.
- Cannot enable portfolio-level features.
- All other user management actions do not apply to this role.
- Cannot approve new Bitsight Vendor Risk Management users.
- Cannot assign roles.
- Cannot enable features for a user.
- Cannot enable portfolio-level features.
- All other user management actions do not apply to this role.
- Cannot access the activity log, assign roles, assign contacts, or enable features.
- Cannot enable portfolio-level features.
- Can be a collaboration contact.
- Cannot be a subscription contact.
- Can enable company request notifications if they own them.
- Cannot generate a Platform Usage report.
- Approving new Bitsight Vendor Risk Management users does not apply to this role.
- Cannot approve new Bitsight Vendor Risk Management users.
- Cannot assign roles.
- Cannot enable features for a user.
- Cannot enable portfolio-level features.
- All other user management actions do not apply to this role.
By action
Permissions key
✅ = Is permitted.
❌ = Not permitted.
➖ = Not applicable and not permitted.
- Access the activity log
-
✅ Only Admins can do this.
❌ Group Admins, Portfolio Managers, and Users cannot do this.
➖ Not applicable to Internal Business Users, Operations, and View Only.
-
Approve newly Bitsight VRM
users. -
✅ Only Admins can do this.
❌ Internal Business Users, Operations, and View Only cannot do this.
➖ Not applicable to Group Admins, Portfolio Managers, and Users.
- Assign roles or TMH and VRM
roles. -
✅ Admins can assign any role to any user.
✅ Group Admins can assign users in their group the User, Portfolio Manager, or Group Admin role.
❌ All other roles cannot assign roles.
- Assign a collaboration contact
-
✅ Admins can do this.
✅ Group Admins can assign users in their own group only.
❌ Portfolio Managers and Users cannot do this.
➖ Not applicable to Internal Business Users, Operations, and View Only.
- Assign a subscription contact
-
✅ Admins can do this.
✅ Group Admins can assign users in their own group only.
❌ Portfolio Managers and Users cannot do this.
➖ Not applicable to Internal Business Users, Operations, and View Only.
- Be assigned as a collaboration
contact -
✅ Admins, Group Admins, Portfolio Managers, and Users can do this.
➖ Not applicable to Internal Business Users, Operations, and View Only.
- Be assigned as a subscription
contact -
✅ Admins can do this.
✅ Group Admins and Portfolio Managers can be assigned on behalf of the group.
❌ Users cannot do this.
➖ Not applicable to Internal Business Users, Operations, and View Only.
- Enable company request
notifications -
✅ Admins can do this.
✅ Group Admins, Portfolio Managers, and Users can do this if they own the request.
➖ Not applicable to Internal Business Users, Operations, and View Only.
- Enable features for a user.
-
✅ Admins can do this.
✅ Group Admins can enable features for users in their own group only.
❌ Portfolio Managers, Users, Internal Business Users, Operations, and View Only cannot do this.
- Enable portfolio-level features,
such as Dark Web -
✅ Only Admins can do this.
❌ No other role can enable portfolio-level features.
- Generate a Platform Usage
report -
✅ Admins, Group Admins, and Portfolio Managers can do this.
❌ Users cannot do this.
➖ Not applicable to Internal Business Users, Operations, and View Only.
- January 14, 2026: Remove Beacon mentions.
- January 2, 2025: Approve new Legacy Bitsight VRM and Beacon users; Company Request notifications.
- December 17, 2024: Enable portfolio-level feature (Dark Web).
- November 22, 2024: Separated from User Permissions and added VRM/TMH roles.
Comments
Please sign in to leave a comment.