Manage Team Members (Mondoo Users)
Invite team members and assign roles to control access to Mondoo organizations and spaces.
You add team members (Mondoo users) and assign them roles that control what they can see and do. Membership is scoped to either an organization (access to every space in it, including spaces created later) or a single space.
You manage people on the Identity & Access settings page of an organization or a space. The organization page has three groups: Users, Teams, and Service accounts. The space page has Users and Service accounts. To learn about teams, read Manage access with OIDC group claims and teams. To learn about service accounts, read Create and manage service accounts.

How roles work
Every user gets one role plus any number of extra permissions:
- Role is the primary choice: Viewer, Editor, or Admin. Each role grants a default set of permissions. Admin is the console label for the Owner role; APIs, Terraform, and SCIM mappings still call it
owner. - Permissions are the fine-grained roles listed under Permissions. You can add permissions on top of a role, or choose Custom to grant only the permissions you pick, with no primary role.
- Service account roles apply to non-human identities like agents and CI pipelines. You assign them through service accounts, not through team member invites.
A user's access is the union of everything granted to them, whether directly, through a team, or at the organization level. Every role is scoped to an organization or to a single space.
The Organization role or Space role column on the Identity & Access page summarizes each user's access, for example Viewer, Admin, Editor + 1 permission, or Custom · 3 permissions.
Roles
| Role | Scope | What they can do |
|---|---|---|
| Admin (Owner) | Organization, space | Full administrative control of an organization or space, including user, policy, integration, and billing management. Admin includes every permission in the Permissions list. |
| Editor | Organization, space | Day-to-day administration of policies, integrations, assets, workflows, and content. Editors cannot create or delete organizations and spaces, manage billing, review exceptions, or configure SSO. By default, Editor includes these permissions: Agent Manager, API Token Creator, API Token Manager, Asset Manager, Compliance Framework Manager, Exception Requester, Export User, Integrations Manager, Policy Editor, Policy Manager, Risk Factor Manager, Security Pipeline User, Service Account Creator, Service Account Manager, SLA Manager, Ticket Creator, Ticket Manager, User Manager, Vulnerability Exchange Manager, and Workflow Manager. |
| Viewer | Organization, space | Read-only access to assets, findings, vulnerabilities, policies, compliance, dashboards, and reports. Viewer includes none of the permissions below; add the ones you need. |
Every team member also implicitly receives the Org Member role on their organization and the Space Member role on each space they can access. These baseline roles grant minimal read access, such as seeing that an organization or space exists. You don't assign them directly.
Permissions
Add these permissions to a role to grant targeted access without giving the team member a broader role. For example, give a user the Viewer role plus Exception Reviewer so they can approve exceptions without making other changes. Because permissions are the union of everything a person holds, you can compose a near-Admin identity by starting from Custom and deliberately leaving out the one capability you don't want to delegate.
These are the permissions the Mondoo Console offers, grouped by area. The Customize permissions page shows the same one-line summary for each.
Identity and access
| Permission | Scope | What they can do |
|---|---|---|
| IAM Manager | Organization, space, platform | Assign and remove user roles at space, organization, and platform scope, manage workload identity federation (WIF) bindings, and configure SSO. This is the most powerful delegation role: a holder can grant any customer-facing role and can therefore self-escalate, so it sits above Owner in the role hierarchy. Only a Platform Admin or an existing IAM Manager can grant it. Assign it sparingly. |
| User Manager | Organization, space | Add and remove users and manage their space and organization role assignments. A lighter alternative to IAM Manager for delegating user administration: it cannot manage WIF, SSO, or platform memberships. Like every role, it can never grant a role higher than its own (it cannot mint Owners or IAM Managers). Combine with Team Manager to fully manage individual users and teams. |
Organizations and spaces
| Permission | Scope | What they can do |
|---|---|---|
| Organization Manager | Organization | Create, update, and delete organizations. |
| Space Manager | Space | Create, update, deactivate, reactivate, and delete spaces, and set resource contacts. |
Teams
| Permission | Scope | What they can do |
|---|---|---|
| Team Manager | Organization, space | Create, update, and delete teams, and manage team membership. |
| Team Member Manager | Team | Add and remove members of the specific team this role is assigned to. You don't grant it from the permissions list: on a team's detail page, turn on Member Manager for a member of that team. |
Policies and query packs
| Permission | Scope | What they can do |
|---|---|---|
| Policy Editor | Space | Author, edit, and validate policy bundles and read the policy registry. Cannot assign or unassign policies. |
| Policy Manager | Space | Full policy lifecycle: edit, validate, delete, and assign or unassign policies; set policy properties; read aggregate scores and exceptions tied to those policies. |
| Query Pack Editor | Space | Author and edit query pack bundles and browse the query and resource registry. |
| Query Pack Manager | Space | Author and manage query pack bundles and browse the query and resource registry. |
Exceptions
| Permission | Scope | What they can do |
|---|---|---|
| Exception Requester | Space | File exception requests on findings and extend existing exceptions. Cannot approve them. |
| Exception Reviewer | Space | Approve or deny exception requests submitted by others and extend exception review periods. |
| Exception Manager | Space | Request, review, and delete security findings exceptions. |
Cases and tickets
| Permission | Scope | What they can do |
|---|---|---|
| Ticket Creator | Space | Create and update cases and push them to connected ticketing integrations like Jira. Cannot close or delete cases. |
| Ticket Manager | Space | Full case lifecycle: create, update, close, delete, and process case events, plus create, update, and close tickets in connected ticketing integrations. |
Integrations and SLAs
| Permission | Scope | What they can do |
|---|---|---|
| Integrations Manager | Space | Create, update, delete, and operate integrations: get integration tokens, trigger actions, run discovery, suppress messages, and manage integration settings. |
| SLA Manager | Space | Read and update the security model used to configure SLAs, plus read policies, compliance frameworks, findings, and aggregate scores so SLA performance can be monitored. |
Assets
| Permission | Scope | What they can do |
|---|---|---|
| Asset Manager | Space | Create and delete assets and annotations, delete CI/CD projects, and manage asset routing. |
Agents
| Permission | Scope | What they can do |
|---|---|---|
| Agent Manager | Space | Create, update, and delete managed agents, and generate, list, and revoke registration tokens to enroll them. Read-only agent access is already covered by Viewer. |
Workspaces
| Permission | Scope | What they can do |
|---|---|---|
| Workspace Manager | Space | Create, update, and delete workspaces. |
Workflows
| Permission | Scope | What they can do |
|---|---|---|
| Workflow Manager | Space | Create, update, delete, cancel, and execute workflows and scheduled workflows. |
Compliance and risk
| Permission | Scope | What they can do |
|---|---|---|
| Compliance Framework Manager | Space | Manage and delete compliance frameworks. |
| Risk Factor Manager | Space | Create and modify risk factors. |
Vulnerability data
| Permission | Scope | What they can do |
|---|---|---|
| Vulnerability Exchange Manager | Space | Upload, edit, and delete VEX documents, upload FEX findings, and close findings. |
Auditing
| Permission | Scope | What they can do |
|---|---|---|
| Audit Log Viewer | Organization, space | View the audit log. |
Pipelines and exports
| Permission | Scope | What they can do |
|---|---|---|
| Security Pipeline User | Space | Open pull requests through a security pipeline integration, such as GitOps remediation PRs. |
| Export User | Space | Generate and delete documents (report exports). |
Agent credentials
Delegate management of the credentials agents and automation use to authenticate, without granting a broader role.
| Permission | Scope | What they can do |
|---|---|---|
| API Token Creator | Space | Generate, update, and list API tokens. Cannot delete them. |
| API Token Manager | Space | Full API token lifecycle: generate, update, list, and delete API tokens. |
| Service Account Creator | Space | Create, update, list, and view service accounts; manage service account memberships; and read the public key. Cannot delete service accounts. |
| Service Account Manager | Space | Full service account lifecycle: everything the Service Account Creator can do, plus delete service accounts. |
| Registration Token Creator | Space | Generate, list, and verify registration tokens. Cannot revoke them. |
| Registration Token Manager | Space | Full registration token lifecycle: generate, list, verify, and revoke registration tokens. |
Roles you assign outside the console
Mondoo also defines a few user roles that the Mondoo Console doesn't offer in its permissions list. You can assign them with the API or the Mondoo Terraform provider:
| Role | Scope | What they can do |
|---|---|---|
| Billing Manager | Organization | Manage the billing account and subscription, including opening billing sessions and updating subscription settings. |
| Policy Analytics Dashboard Viewer | Organization, space | Read-only access to the policy analytics view, including the list of policies for analytics, the workspace, assets and their assigned policies, and resource contacts. |
| BI Viewer | Space | View business intelligence dashboards and run BI queries, including dashboard versions and scheduled exports. |
Service account roles
These roles apply to non-human identities. When you create a service account in the Mondoo Console, you can pick Viewer, Editor, Owner, Agent, and Export Runner. Mondoo assigns the others to the service accounts it creates for integrations and automation.
| Role | Scope | What it allows |
|---|---|---|
| Agent | Space | Used by cnspec agents. Register, report health, sync assets, resolve assigned policies, and upload scan results. |
| Export Runner | Space | Used by export integrations that pull data out of Mondoo. Read assets, findings, scores, and reports across the space hierarchy, plus upload documents and report status. |
| Gateway Agent | Space | Used by gateway-mode agents that proxy other agents. Enroll and proxy for downstream agents, sync their assets, and manage their policy bundles. |
| Scan Job Runner | Space | Minimal role for automated scan jobs: sync assets, resolve policies, and store scan results. |
| VEX Importer | Space | Used by tools that bulk upload VEX, FEX, and SBOM data. Upload, edit, and delete VEX documents, FEX findings, and SBOMs. |
| Deployment Manager | Space | Used by deployment automation. Create, update, and delete integrations for automated deployments. |
| SCIM Identity Manager | Organization | Used by SCIM provisioning clients such as Okta and Microsoft Entra ID. Provision and deprovision users and groups. |
| Platform Admin | Organization, space | Used by automated Mondoo Platform tooling and operators that need full system control. Full platform-wide control over all organizations, spaces, users, and resources. |
Add a team member
The procedure is the same whether you're adding someone to an organization or to a single space. The scope is set by where you start.
-
Navigate to the organization or space you want to add the user to.
-
In the side navigation bar, select Settings, then Identity & Access.
-
Select ADD USER.

-
In the User email box, enter the user's email address.
-
Under Role, select Viewer, Editor, or Admin.
To pick individual permissions instead, select Custom. Mondoo opens the full Customize permissions page, where you can pick a base role and turn individual permissions on or off. (Custom is available once you enter a valid email address.)
-
Select ADD USER.
The user gains access right away with the role you assigned. If the person doesn't have a Mondoo account yet, they appear with the status Pending until they sign up. To grant access across the whole organization, add the user from the organization's Identity & Access page.
Edit a team member's role
-
Navigate to the organization or space in which you want to edit a user's access.
-
In the side navigation bar, select Settings, then Identity & Access.
-
Change the role in one of these ways:
-
Switch to a different role: In the user's row, select the current role (for example, Viewer) in the Organization role or Space role column. Select Viewer, Editor, or Admin, then confirm the change.
-
Add or remove individual permissions: Select the current role and then Customize. On the Customize permissions page, pick a base role. Permissions the role grants are on by default and show the role in the From column. Toggle any permission to add it or remove it, then select SAVE CHANGES and confirm.

-
Change several users at once: Select the checkboxes next to the users, then select EDIT ROLE in the bar at the bottom of the page.
-
To see and change everything a user can access, select their name. The detail page shows their Organization role and, at the organization level, a Space access table where you can set a role for each space.
Remove a team member
-
Navigate to the organization or space from which you want to remove a user's access.
-
In the side navigation bar, select Settings, then Identity & Access.
-
Select the checkbox next to each user you want to remove.
-
In the bar at the bottom of the page, select REMOVE, then confirm. The users lose all access granted in that organization or space.

Where selected permissions work
This table covers the fine-grained permissions above. Each is meant to be combined with Viewer (Viewer provides read access so the pages render; the permission enables the actions on them). It lists the console pages each permission is designed to use. Permissions not listed here (for example Policy Manager, Ticket Manager, Integrations Manager, or the agent-credential permissions) take effect on the pages implied by their descriptions above.
| Permission | Pages it works on |
|---|---|
| IAM Manager | Organization Settings → Identity & Access, Authentication (SSO), and Workload Identity; Space Settings → Identity & Access and Workload Identity |
| User Manager | Organization and Space Settings → Identity & Access (add and remove users and set their roles) |
| Organization Manager | Organization Settings → General; the organizations list and the create organization dialog |
| Space Manager | Organization → Spaces (including create space); Space Settings → General |
| Team Manager | Organization Settings → Identity & Access → Teams (and individual team detail) |
| Agent Manager | Space → Integrations → Managed (agents); Space Settings → Registration Tokens (including generate); add a server or agent integration |
| Asset Manager | Space → Inventory, CI/CD |
| Workspace Manager | Space → Workspaces (list, create, and per-workspace settings) |
| Compliance Framework Manager | Space → Compliance (frameworks and framework detail) |
| Risk Factor Manager | Space → Security Model → Risk Score Control |
| Audit Log Viewer | Organization and Space Settings → Audit Log |
| Vulnerability Exchange Manager | VEX document, FEX upload, and close-findings operations through the API |
| Exception Manager | Space → Findings → Exceptions (and the create-exception flow on findings and controls) |
| Security Pipeline User | Space → Findings (the "fix via pull request" action) and Space → Integrations → Security Pipeline |
| Export User | Space → Reporting (generate, download, and delete report exports) |