Remediation & mitigation permissions by role and by action

Remediation and mitigation tools help users track and resolve findings. This article covers exposed credentials data, company notes, the Asset Risk Matrix, finding comments, Issue Tracking, and Work From Home. A user's role determines who can use each tool. For company notes and finding comments, Portfolio Managers and Users can change only the items they own. This article lists the remediation and mitigation permissions for each role and for each action.

Roles referenced on this page: Users with the Admin, Group Admin, Portfolio Manager, Operations, Internal Business User, User, or View Only role.

What can my role do?

Use this section to find everything a specific role can and can't do with remediation and mitigation tools. For a breakdown by action instead, see By action below.

What can an Admin do with remediation and mitigation tools?
  • Can download exposed credentials data for your organization and view the Identity Intelligence Preview card.
  • Can edit or delete company notes.
  • Can customize the Asset Risk Matrix.
  • Can edit or delete finding comments.
  • Can view findings and assign users to remediate them in Issue Tracking.
  • Can choose whether Bitsight automatically triggers a rescan when a finding's remediation status is set to Resolved.
  • Can use Work From Home.
What can a Group Admin do with remediation and mitigation tools?
  • Can download exposed credentials data for your organization and view the Identity Intelligence Preview card.
  • Cannot edit or delete company notes.
  • Cannot customize the Asset Risk Matrix.
  • Cannot edit or delete finding comments.
  • Can view findings and assign users to remediate them in Issue Tracking, for findings in their group.
  • Cannot choose whether Bitsight automatically triggers a rescan.
  • Cannot use Work From Home.
What can a Portfolio Manager do with remediation and mitigation tools?
  • Cannot download exposed credentials data or view the Identity Intelligence Preview card.
  • Can edit or delete company notes they own.
  • Cannot customize the Asset Risk Matrix.
  • Can edit or delete finding comments they own.
  • Can view findings and assign users to remediate them in Issue Tracking, for findings in their group.
  • Cannot choose whether Bitsight automatically triggers a rescan.
  • Cannot use Work From Home.
What can an Operations user do with remediation and mitigation tools?
  • Remediation and mitigation permissions do not apply to this role.
What can an Internal Business User do with remediation and mitigation tools?
  • Remediation and mitigation permissions do not apply to this role.
What can a User do with remediation and mitigation tools?
  • Cannot download exposed credentials data or view the Identity Intelligence Preview card.
  • Can edit or delete company notes they own.
  • Cannot customize the Asset Risk Matrix.
  • Can edit or delete finding comments they own.
  • Can view findings and assign users to remediate them in Issue Tracking, for findings in their group.
  • Cannot choose whether Bitsight automatically triggers a rescan.
  • Cannot use Work From Home.
What can a View Only user do with remediation and mitigation tools?
  • Remediation and mitigation permissions do not apply to this role.

By action

Permissions key

✅ = Is permitted.

❌ = Not permitted.

➖ = Not applicable and not permitted.

Download exposed 
credentials data for 
your organization

✅ Admins and Group Admins can do this.

❌ Portfolio Managers and Users cannot do this.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

View the Identity Intelligence 
Preview card.

✅ Admins and Group Admins can do this.

❌ Portfolio Managers and Users cannot do this.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Edit or delete company notes

✅ Admins can edit or delete company notes.

✅ Portfolio Managers and Users can edit or delete company notes they own only.

❌ Group Admins cannot do this.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Customize the Asset Risk Matrix

✅ Only Admins can do this.

❌ No other role can customize the Asset Risk Matrix.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Edit or delete finding comments

✅ Admins can edit or delete finding comments.

✅ Portfolio Managers and Users can edit or delete finding comments they own only.

❌ Group Admins cannot do this.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

View findings and assign 
users to remediate them 
(Issue Tracking)

✅ Admins can do this.

✅ Group Admins, Portfolio Managers, and Users can view and assign findings in their own group only.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Issue Tracking: rescan

Choose whether to automatically trigger a rescan when a finding's remediation status is set to Resolved.

✅ Only Admins can do this.

❌ No other role can choose this setting.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Use Work From Home

✅ Only Admins can do this.

❌ No other role can use Work From Home.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Publish Date or Recent Edits
  • March 25, 2025: Identity Intelligence Preview.
  • February 28, 2025: Automatically trigger a rescan when a finding's remediation status is set to Resolved.
  • January 3, 2025: Customize the Asset Risk Matrix.
Was this article helpful?
1 out of 1 found this helpful

Comments

0 comments

Please sign in to leave a comment.