Manage MondooManage Access to Mondoo

Manage Team Members (Mondoo Users)

Invite team members and assign roles to control access to Mondoo organizations and spaces.

You add team members (Mondoo users) and assign them roles that control what they can see and do. Membership is scoped to either an organization (access to every space in it, including spaces created later) or a single space.

You manage people on the Identity & Access settings page of an organization or a space. The organization page has three groups: Users, Teams, and Service accounts. The space page has Users and Service accounts. To learn about teams, read Manage access with OIDC group claims and teams. To learn about service accounts, read Create and manage service accounts.

The organization Identity & Access page in the Mondoo Console, listing users with their status and organization role

How roles work

Every user gets one role plus any number of extra permissions:

  • Role is the primary choice: Viewer, Editor, or Admin. Each role grants a default set of permissions. Admin is the console label for the Owner role; APIs, Terraform, and SCIM mappings still call it owner.
  • Permissions are the fine-grained roles listed under Permissions. You can add permissions on top of a role, or choose Custom to grant only the permissions you pick, with no primary role.
  • Service account roles apply to non-human identities like agents and CI pipelines. You assign them through service accounts, not through team member invites.

A user's access is the union of everything granted to them, whether directly, through a team, or at the organization level. Every role is scoped to an organization or to a single space.

The Organization role or Space role column on the Identity & Access page summarizes each user's access, for example Viewer, Admin, Editor + 1 permission, or Custom · 3 permissions.

Roles

RoleScopeWhat they can do
Admin (Owner)Organization, spaceFull administrative control of an organization or space, including user, policy, integration, and billing management. Admin includes every permission in the Permissions list.
EditorOrganization, spaceDay-to-day administration of policies, integrations, assets, workflows, and content. Editors cannot create or delete organizations and spaces, manage billing, review exceptions, or configure SSO. By default, Editor includes these permissions: Agent Manager, API Token Creator, API Token Manager, Asset Manager, Compliance Framework Manager, Exception Requester, Export User, Integrations Manager, Policy Editor, Policy Manager, Risk Factor Manager, Security Pipeline User, Service Account Creator, Service Account Manager, SLA Manager, Ticket Creator, Ticket Manager, User Manager, Vulnerability Exchange Manager, and Workflow Manager.
ViewerOrganization, spaceRead-only access to assets, findings, vulnerabilities, policies, compliance, dashboards, and reports. Viewer includes none of the permissions below; add the ones you need.

Every team member also implicitly receives the Org Member role on their organization and the Space Member role on each space they can access. These baseline roles grant minimal read access, such as seeing that an organization or space exists. You don't assign them directly.

Permissions

Add these permissions to a role to grant targeted access without giving the team member a broader role. For example, give a user the Viewer role plus Exception Reviewer so they can approve exceptions without making other changes. Because permissions are the union of everything a person holds, you can compose a near-Admin identity by starting from Custom and deliberately leaving out the one capability you don't want to delegate.

These are the permissions the Mondoo Console offers, grouped by area. The Customize permissions page shows the same one-line summary for each.

Identity and access

PermissionScopeWhat they can do
IAM ManagerOrganization, space, platformAssign and remove user roles at space, organization, and platform scope, manage workload identity federation (WIF) bindings, and configure SSO. This is the most powerful delegation role: a holder can grant any customer-facing role and can therefore self-escalate, so it sits above Owner in the role hierarchy. Only a Platform Admin or an existing IAM Manager can grant it. Assign it sparingly.
User ManagerOrganization, spaceAdd and remove users and manage their space and organization role assignments. A lighter alternative to IAM Manager for delegating user administration: it cannot manage WIF, SSO, or platform memberships. Like every role, it can never grant a role higher than its own (it cannot mint Owners or IAM Managers). Combine with Team Manager to fully manage individual users and teams.

Organizations and spaces

PermissionScopeWhat they can do
Organization ManagerOrganizationCreate, update, and delete organizations.
Space ManagerSpaceCreate, update, deactivate, reactivate, and delete spaces, and set resource contacts.

Teams

PermissionScopeWhat they can do
Team ManagerOrganization, spaceCreate, update, and delete teams, and manage team membership.
Team Member ManagerTeamAdd and remove members of the specific team this role is assigned to. You don't grant it from the permissions list: on a team's detail page, turn on Member Manager for a member of that team.

Policies and query packs

PermissionScopeWhat they can do
Policy EditorSpaceAuthor, edit, and validate policy bundles and read the policy registry. Cannot assign or unassign policies.
Policy ManagerSpaceFull policy lifecycle: edit, validate, delete, and assign or unassign policies; set policy properties; read aggregate scores and exceptions tied to those policies.
Query Pack EditorSpaceAuthor and edit query pack bundles and browse the query and resource registry.
Query Pack ManagerSpaceAuthor and manage query pack bundles and browse the query and resource registry.

Exceptions

PermissionScopeWhat they can do
Exception RequesterSpaceFile exception requests on findings and extend existing exceptions. Cannot approve them.
Exception ReviewerSpaceApprove or deny exception requests submitted by others and extend exception review periods.
Exception ManagerSpaceRequest, review, and delete security findings exceptions.

Cases and tickets

PermissionScopeWhat they can do
Ticket CreatorSpaceCreate and update cases and push them to connected ticketing integrations like Jira. Cannot close or delete cases.
Ticket ManagerSpaceFull case lifecycle: create, update, close, delete, and process case events, plus create, update, and close tickets in connected ticketing integrations.

Integrations and SLAs

PermissionScopeWhat they can do
Integrations ManagerSpaceCreate, update, delete, and operate integrations: get integration tokens, trigger actions, run discovery, suppress messages, and manage integration settings.
SLA ManagerSpaceRead and update the security model used to configure SLAs, plus read policies, compliance frameworks, findings, and aggregate scores so SLA performance can be monitored.

Assets

PermissionScopeWhat they can do
Asset ManagerSpaceCreate and delete assets and annotations, delete CI/CD projects, and manage asset routing.

Agents

PermissionScopeWhat they can do
Agent ManagerSpaceCreate, update, and delete managed agents, and generate, list, and revoke registration tokens to enroll them. Read-only agent access is already covered by Viewer.

Workspaces

PermissionScopeWhat they can do
Workspace ManagerSpaceCreate, update, and delete workspaces.

Workflows

PermissionScopeWhat they can do
Workflow ManagerSpaceCreate, update, delete, cancel, and execute workflows and scheduled workflows.

Compliance and risk

PermissionScopeWhat they can do
Compliance Framework ManagerSpaceManage and delete compliance frameworks.
Risk Factor ManagerSpaceCreate and modify risk factors.

Vulnerability data

PermissionScopeWhat they can do
Vulnerability Exchange ManagerSpaceUpload, edit, and delete VEX documents, upload FEX findings, and close findings.

Auditing

PermissionScopeWhat they can do
Audit Log ViewerOrganization, spaceView the audit log.

Pipelines and exports

PermissionScopeWhat they can do
Security Pipeline UserSpaceOpen pull requests through a security pipeline integration, such as GitOps remediation PRs.
Export UserSpaceGenerate and delete documents (report exports).

Agent credentials

Delegate management of the credentials agents and automation use to authenticate, without granting a broader role.

PermissionScopeWhat they can do
API Token CreatorSpaceGenerate, update, and list API tokens. Cannot delete them.
API Token ManagerSpaceFull API token lifecycle: generate, update, list, and delete API tokens.
Service Account CreatorSpaceCreate, update, list, and view service accounts; manage service account memberships; and read the public key. Cannot delete service accounts.
Service Account ManagerSpaceFull service account lifecycle: everything the Service Account Creator can do, plus delete service accounts.
Registration Token CreatorSpaceGenerate, list, and verify registration tokens. Cannot revoke them.
Registration Token ManagerSpaceFull registration token lifecycle: generate, list, verify, and revoke registration tokens.

Roles you assign outside the console

Mondoo also defines a few user roles that the Mondoo Console doesn't offer in its permissions list. You can assign them with the API or the Mondoo Terraform provider:

RoleScopeWhat they can do
Billing ManagerOrganizationManage the billing account and subscription, including opening billing sessions and updating subscription settings.
Policy Analytics Dashboard ViewerOrganization, spaceRead-only access to the policy analytics view, including the list of policies for analytics, the workspace, assets and their assigned policies, and resource contacts.
BI ViewerSpaceView business intelligence dashboards and run BI queries, including dashboard versions and scheduled exports.

Service account roles

These roles apply to non-human identities. When you create a service account in the Mondoo Console, you can pick Viewer, Editor, Owner, Agent, and Export Runner. Mondoo assigns the others to the service accounts it creates for integrations and automation.

RoleScopeWhat it allows
AgentSpaceUsed by cnspec agents. Register, report health, sync assets, resolve assigned policies, and upload scan results.
Export RunnerSpaceUsed by export integrations that pull data out of Mondoo. Read assets, findings, scores, and reports across the space hierarchy, plus upload documents and report status.
Gateway AgentSpaceUsed by gateway-mode agents that proxy other agents. Enroll and proxy for downstream agents, sync their assets, and manage their policy bundles.
Scan Job RunnerSpaceMinimal role for automated scan jobs: sync assets, resolve policies, and store scan results.
VEX ImporterSpaceUsed by tools that bulk upload VEX, FEX, and SBOM data. Upload, edit, and delete VEX documents, FEX findings, and SBOMs.
Deployment ManagerSpaceUsed by deployment automation. Create, update, and delete integrations for automated deployments.
SCIM Identity ManagerOrganizationUsed by SCIM provisioning clients such as Okta and Microsoft Entra ID. Provision and deprovision users and groups.
Platform AdminOrganization, spaceUsed by automated Mondoo Platform tooling and operators that need full system control. Full platform-wide control over all organizations, spaces, users, and resources.

Add a team member

The procedure is the same whether you're adding someone to an organization or to a single space. The scope is set by where you start.

  1. Navigate to the organization or space you want to add the user to.

  2. In the side navigation bar, select Settings, then Identity & Access.

  3. Select ADD USER.

    The Add User dialog in the Mondoo Console, with a User email box and Viewer, Editor, Admin, and Custom role choices

  4. In the User email box, enter the user's email address.

  5. Under Role, select Viewer, Editor, or Admin.

    To pick individual permissions instead, select Custom. Mondoo opens the full Customize permissions page, where you can pick a base role and turn individual permissions on or off. (Custom is available once you enter a valid email address.)

  6. Select ADD USER.

The user gains access right away with the role you assigned. If the person doesn't have a Mondoo account yet, they appear with the status Pending until they sign up. To grant access across the whole organization, add the user from the organization's Identity & Access page.

Edit a team member's role

  1. Navigate to the organization or space in which you want to edit a user's access.

  2. In the side navigation bar, select Settings, then Identity & Access.

  3. Change the role in one of these ways:

    • Switch to a different role: In the user's row, select the current role (for example, Viewer) in the Organization role or Space role column. Select Viewer, Editor, or Admin, then confirm the change.

    • Add or remove individual permissions: Select the current role and then Customize. On the Customize permissions page, pick a base role. Permissions the role grants are on by default and show the role in the From column. Toggle any permission to add it or remove it, then select SAVE CHANGES and confirm.

      The Customize permissions page, with a base role selector and a list of permissions showing which ones come from the Editor role

    • Change several users at once: Select the checkboxes next to the users, then select EDIT ROLE in the bar at the bottom of the page.

To see and change everything a user can access, select their name. The detail page shows their Organization role and, at the organization level, a Space access table where you can set a role for each space.

Remove a team member

  1. Navigate to the organization or space from which you want to remove a user's access.

  2. In the side navigation bar, select Settings, then Identity & Access.

  3. Select the checkbox next to each user you want to remove.

  4. In the bar at the bottom of the page, select REMOVE, then confirm. The users lose all access granted in that organization or space.

    The Remove user confirmation dialog on the space Identity & Access page

Where selected permissions work

This table covers the fine-grained permissions above. Each is meant to be combined with Viewer (Viewer provides read access so the pages render; the permission enables the actions on them). It lists the console pages each permission is designed to use. Permissions not listed here (for example Policy Manager, Ticket Manager, Integrations Manager, or the agent-credential permissions) take effect on the pages implied by their descriptions above.

PermissionPages it works on
IAM ManagerOrganization Settings → Identity & Access, Authentication (SSO), and Workload Identity; Space Settings → Identity & Access and Workload Identity
User ManagerOrganization and Space Settings → Identity & Access (add and remove users and set their roles)
Organization ManagerOrganization Settings → General; the organizations list and the create organization dialog
Space ManagerOrganization → Spaces (including create space); Space Settings → General
Team ManagerOrganization Settings → Identity & Access → Teams (and individual team detail)
Agent ManagerSpace → Integrations → Managed (agents); Space Settings → Registration Tokens (including generate); add a server or agent integration
Asset ManagerSpace → Inventory, CI/CD
Workspace ManagerSpace → Workspaces (list, create, and per-workspace settings)
Compliance Framework ManagerSpace → Compliance (frameworks and framework detail)
Risk Factor ManagerSpace → Security Model → Risk Score Control
Audit Log ViewerOrganization and Space Settings → Audit Log
Vulnerability Exchange ManagerVEX document, FEX upload, and close-findings operations through the API
Exception ManagerSpace → Findings → Exceptions (and the create-exception flow on findings and controls)
Security Pipeline UserSpace → Findings (the "fix via pull request" action) and Space → Integrations → Security Pipeline
Export UserSpace → Reporting (generate, download, and delete report exports)

On this page