Skip to content
Vulnotes LogoVulnotes
Roles & Permissions

Roles & Permissions

Vulnotes uses role-based access control (RBAC) to determine what each user can do. Users can hold several roles; their permissions are combined. Team restrictions then determine which clients, reports, and templates they can access.

Roles management

Built-in roles

Fresh installations include three built-in roles:

  • Admin - full access to everything, including user management, settings, and all data
  • Pentester - can create and edit reports, findings, vulnerabilities, and companies, but cannot access administration settings
  • Viewer - read-only access to reports, templates, vulnerabilities, and clients

You can create additional roles to match your organization's structure.

Permission categories

Permissions are organized by feature. Most use View (ro:) and Edit (rw:), where edit includes read access. Some actions have separate permissions, such as managing planning or reading the audit trail.

The main permission categories include:

  • Reports - create, view, edit, delete, export reports
  • Findings - covered by report permissions
  • Templates - manage report templates
  • Vulnerabilities - manage the vulnerability library and templates
  • Companies - manage clients and contacts
  • Users - view and manage other users
  • Settings - access administration settings
  • Planning - create and manage events
  • Audit Logs - read the audit trail; verification and export require system administration

Creating custom roles

Go to Administration > Roles & Permissions and click Add Role. Give your role a name, then toggle permissions on or off for each category.

Role permission