Understand roles
Last updated: Jun 23, 2026
Members on the Fluid Attacks platform have distinct roles with associated permissions. You can view your role within the organization or group you are navigating in the user menu, which is in the upper-right corner of your screen.
This page explains the different roles that are available on the platform, along with the permissions they grant.
Organization-level roles
Organization Manager role
Members assigned the Organization Manager role are automatically granted the Group Manager role within all groups belonging to the organization.
Designed for technical leaders within their organization, this role provides access to all privileges on the platform available to clients, especially enabling them to handle credentials, billing, members, and policy settings, on top of the vulnerability management functions granted to other client roles.
User role (organization level)
Members with a User role at the organization level have permission to be read-only dashboard viewers for the organization. The role lets a stakeholder see the organization's aggregate security posture, compliance standing, credentials list, and groups list (only those they have been invited to, if any). They cannot, for example, add members, change policy or payment settings, or do anything destructive like removing credentials or members. Within groups, they can be granted any of the three roles available for clients: Group Manager, User, or Vulnerability Manager.
Group-level roles
Group Manager role
Designed for technical leaders within their group, this role allows them to perform all actions available to clients in the group on the platform. It is designed for product leaders, granting exclusive capabilities like generating testing certificates, accepting vulnerabilities permanently, approving vulnerability deletion requests by their company, managing group information, managing group members, deactivating and moving Git repositories, adding exclusions, and more (details below).
User role
This is the role most members are given within a group. It is typically assigned to developers responsible for remediating vulnerabilities. Members with this role can access vulnerability information, request reattacks, update treatments, make false positive requests, add and remove tags, and post comments. They can also manage the testing scope by adding Git repositories, IP roots, URL roots, and environment secrets manage CI Gate tokens, upload and delete threat model files, add and download group files, create and remove portfolios, and request event verifications. At the organization level, they can download compliance reports and submit vulnerabilities for temporary or permanent acceptance.
Vulnerability Manager role
Intended for technical leaders within their group, this role grants additional oversight capabilities on top of the User role. Vulnerability Managers can generate reports, view group members, assign fix work to members, and approve or reject treatment acceptance requests. They also have all the group-level permissions of the User role, like managing testing scope, CI Gate tokens, and threat model files, as well as requesting reattacks, updating treatments, and posting comments on vulnerabilities, among those already mentioned. The Vulnerability Manager role at the organization level does not exist.
Permissions
Below are the descriptions of the permissions available to clients on Fluid Attacks' platform. These permissions are categorized into two levels: the group and organization levels.
CI Gate
- Generate/update CI Gate token: Generate and update the token to use for the CI Gate, an application that inspects builds for noncompliance with organization policies and prevents deployment if it finds any. Available at DevSecOps > Manage token > Generate/Reset.
- View CI Gate token and its expiration date: View the current CI Gate token and when it expires. Available at DevSecOps > Manage token > Reveal token.
- View CI Gate executions: Access to reports of executions of the CI Gate in your CI/CD. Available at DevSecOps.
Design Map
-
Add threat model files: Upload threat model files that are correlated with the vulnerabilities reported by Fluid Attacks. Available at Design Map > Files > Add.
-
Delete threat model files: Delete threat model files that are correlated with the vulnerabilities reported by Fluid Attacks. Available at Design Map > Files > Delete.
Events
- Request verification on events: Request verification that events have been resolved. Available at Events > Request verification.
- Export file in Events: Download event data as a CSV file. Available at Events > Export.
Files
-
Add file: Upload any files you find helpful or necessary for performing security tests on the group. Available at Scope > Files > Add.
-
Download file: Download files helpful or necessary for performing security tests on the group. Available at Scope > Files > [Click on file] > Download.
-
Delete file: Delete files no longer helpful or necessary for performing security tests on the group. Available at Scope > Files > [Click on file] > Delete.
Group
- Delete group: Delete an unnecessary group. Available at Scope > Delete this group.
- Update group information: Update group information. Available at Scope > Information.
- Use Help options: Access help options for clients to understand vulnerabilities or features, report issues, and more. Available at Help.
Members
- Add member: Invite members to access the group and have some or all vulnerability management functions available to clients. That is, this privilege enables granting any of the three client roles: Group Manager, User, and Vulnerability Manager. Available at Members > Invite a member.
- Delete member: Delete members from the group. Available at Members > Manage members > Delete.
- Update member: Update roles of members. Available at Members > Manage members > Edit.
- View members: View the table of members in the group. Available at Members.
- Invite contributor: Send invitations to contributor developers to register on the platform. Available at Authors > Invite.
Notifications
- Receive notifications: Get notifications related to your group.
- Add hook: Add webhooks that notify of events happening in groups. Available at Integrations > Webhooks > Connect.
- Edit hook: Edit webhooks that notify of events happening in groups. Available at Integrations > Webhooks > Edit.
- Remove hook: Remove webhooks that notify of events happening in groups. Available at Integrations > Webhooks > Edit > Remove.
Portfolio
- Create portfolio tag: Add tags by which to sort groups within an organization. This is useful to get analytics involving specific groups. Available at Scope > Portfolio > Add.
- Remove portfolio tag: Remove a group from a specific portfolio by removing the tag. Available at Scope > Portfolio > Remove.
Reports
- Generate certificate: Generate a certificate of security testing with Fluid Attacks. Available at Vulnerabilities > Generate report > Security testing certificate.
- Generate report: Generate vulnerability reports varying in detail for a specific group. Available at Vulnerabilities > Generate report.
Repositories or roots
- Activate/deactivate repository: Deactivate and activate assets to test. Available at Scope > Git Repositories/IP Roots/URL Roots.
- Move repository: Move a repository with all its associated data to another group. Available at Scope > Git Repositories.
- Sync to Git repository: Clone the Git repository again after changes have been made; this way, Fluid Attacks can test the up-to-date version. Available at Scope.
- Add Git repository: Add Git repositories. Available at Scope > Git Repositories > Add new.
- Edit Git repository: Modify URLs and branches. Available at Scope.
- Add IP root: Add IP addresses to the scope of security testing. Available at Scope.
- Add URL root: Add URLs to the scope of security testing. Available at Scope.
- Edit IP root: Update IP root details. Available at Scope.
- Edit URL root: Update URL root details. Available at Scope.
- Add exclusions: Exclude files or folders from security assessments. Available at Scope.
- Add secrets:
Add secrets
(usernames, passwords, email addresses, tokens, etc.)
that give Fluid Attacks access to environments to test.
Available at Scope.
After adding a secret, you cannot view it again on the platform, and only security analysts assigned to your project may access it.
- Edit secrets: Overwrite a secret's value without the stored value being shown. Available at Scope.
- Remove secrets: Remove unnecessary secrets. Available at Scope.
- Add Git environment: Add environments associated with source code repositories. Available at Scope.
- View Git environment: View environments associated with source code repositories. Available at Scope.
- Edit Git environment: Edit environments associated with source code repositories. Available at Scope.
- Delete Git environment: Delete environments associated with source code repositories. Available at Scope.
- Move Git environment: Move environments associated with source code repositories. Available at Scope.
Vulnerabilities
- Vulnerability assignment: Assign vulnerability remediation responsibilities to team members. Available at Vulnerabilities > [Type] > Locations > Edit.
- False positive request: Request deletion of a vulnerability, as it poses no threat according to the organization. Available at Vulnerabilities > [Type] > Locations > Edit.
- Request reattacks: Request retests by Fluid Attacks' tool to verify the effectiveness of remediation efforts. In the Advanced plan, reattacks may involve both Fluid Attacks' tool and pentesters.
- Approve treatment: Approve or reject submissions for temporary or permanent acceptance of vulnerabilities that require explicit review before taking effect. Available at Vulnerabilities > [Type] > Locations > Treatment acceptance.
- Update treatment: Change the treatments of vulnerabilities. Available at Vulnerabilities > [Type] > Locations > Edit.
- Add tag: Add tags for vulnerabilities. Available at Vulnerabilities > [Type] > Locations > Edit.
- Remove tag: Remove tags from vulnerabilities. Available at Vulnerabilities > [Type] > Locations > Edit.
- Post comments: In the Advanced plan, communicate questions, requests, and suggestions regarding a specific vulnerability or event. In the Essential plan, view comments about reattack outcomes. Available at Vulnerabilities/Events > Comments.
- View reattack assignees: View the staff members currently assigned to perform active reattacks on a weakness. Available at Vulnerabilities.
- View verification assignee: View the staff member currently assigned to verify a specific vulnerability. Available at Vulnerabilities.
Analytics
- Download vulnerability report in Analytics: Download a CSV file of details of all the vulnerabilities reported to the organization. Available at Analytics > Vulnerabilities.
Billing
- Add payment method: Add the payment method linked to the organization. Available at Billing > Payment methods.
- Update payment method: Update the payment method linked to the organization. Available at Billing > Payment methods.
- Download billing file: Download a record of the organization's billing activity. Available at Billing.
Compliance
Download a compliance report: Download a report of compliance with several international standards. Available at Compliance > Standards > Generate report.
Credentials
- Add credentials: Add credentials so Fluid Attacks has access to assets for testing. Available at Credentials > Add credential.
- Remove credentials: Remove credentials, resulting in Fluid Attacks losing access to them. Available at Credentials > Remove.
- Update credentials: Update credentials to maintain Fluid Attacks' access to assets. Available at Credentials > Edit.
- OAuth connection: Authorize Fluid Attacks to import source code repositories from GitLab, GitHub, Bitbucket, and Azure accounts via Open Authorization, which eliminates the need to provide the credentials for these accounts. Available at Credentials > Add credential.
Members
- Add members: Add members with access to the organization's Analytics and Policies sections. That is, this privilege enables granting any of the two client roles at the organization level: Organization Manager and User. Available at Members > Invite a member.
- View member: View members in the organization. Available at Members.
- Update member: Update roles of members. Available at Members > Edit.
- Delete member: Delete members at the organization level. Available at Members > Remove.
Policies
- Update organization/group policies: Manage policies at the organization and group levels. Available at Policies.
- Submit weakness for temporary acceptance in Policies: Submit an org-level policy to temporarily accept all instances of a specific weakness, pending approver review. This is independent of per-vulnerability acceptance: the Days maximum, Acceptances maximum, and Severity range thresholds do not gate this submission. Available at Policies > Acceptance > Temporary acceptance.
- Submit weakness for permanent acceptance in Policies: Submit an org-level policy to permanently accept all instances of a specific weakness. Once approved, all open matching vulnerabilities are permanently accepted and future instances are auto-accepted. Available at Policies > Acceptance > Permanent acceptance.
- Approve and reject weakness for temporary acceptance in Policies: Approve and reject requests to accept vulnerabilities temporarily. Available at Policies > Acceptance > Temporary acceptance.
- Approve and reject weakness for permanent acceptance in Policies: Approve and reject requests to accept vulnerabilities permanently. Available at Policies > Acceptance > Permanent acceptance.
- Update priority score policies: Configure the formula used to calculate vulnerability priority scores. Available at Policies > Priority.
Project
- Add repositories in Outside: Add repositories identified through OAuth access that are not yet part of any group. Available at Outside > Add new roots.
- Add group: Create groups dedicated to managing the vulnerabilities of systems separately. Available at Groups > New group.
- Add organization: Create another organization on the platform. Available on the left side of the top menu of the platform.
The following tables specify the permissions that apply to each role on the platform.
| Feature group | Feature | User | Vulnerability Manager | Group Manager |
| CI Gate | Generate/update CI Gate token | ✅ | ✅ | ✅ |
| CI Gate | View CI Gate token and its expiration date | ✅ | ✅ | ✅ |
| CI Gate | View CI Gate executions | ✅ | ✅ | ✅ |
| Design Map | Add threat model files | ✅ | ✅ | ✅ |
| Design Map | Delete threat model files | ✅ | ✅ | ✅ |
| Events | Request verification on events | ✅ | ✅ | ✅ |
| Events | Export file in Events | ✅ | ✅ | ✅ |
| Files | Add file | ✅ | ✅ | ✅ |
| Files | Download file | ✅ | ✅ | ✅ |
| Files | Delete file | ✅ | ✅ | ✅ |
| Group | Delete group | ❌ | ❌ | ✅ |
| Group | Update group information | ❌ | ❌ | ✅ |
| Group | Use help options (Talk to a Pentester, chat, email) | ✅ | ✅ | ✅ |
| Members | Add member | ❌ | ❌ | ✅ |
| Members | Update member | ❌ | ❌ | ✅ |
| Members | Delete member | ❌ | ❌ | ✅ |
| Members | View members | ❌ | ✅ | ✅ |
| Members | Invite contributor | ❌ | ❌ | ✅ |
| Notifications | Receive notifications | ✅ | ✅ | ✅ |
| Notifications | Add hook | ❌ | ❌ | ✅ |
| Notifications | Edit hook | ❌ | ❌ | ✅ |
| Notifications | Remove hook | ❌ | ❌ | ✅ |
| Portfolio | Create portfolio tag | ✅ | ✅ | ✅ |
| Portfolio | Remove portfolio tag | ✅ | ✅ | ✅ |
| Reports | Generate certificate | ❌ | ❌ | ✅ |
| Reports | Generate report | ❌ | ✅ | ✅ |
| Repositories or roots | Activate/deactivate repository/root | ❌ | ❌ | ✅ |
| Repositories or roots | Move repository/root | ❌ | ❌ | ✅ |
| Repositories or roots | Sync to Git repository | ✅ | ✅ | ✅ |
| Repositories or roots | Add Git repository | ✅ | ✅ | ✅ |
| Repositories or roots | Edit Git repository | ❌ | ❌ | ✅ |
| Repositories or roots | Add IP root | ✅ | ✅ | ✅ |
| Repositories or roots | Edit IP root | ✅ | ✅ | ✅ |
| Repositories or roots | Add URL root | ✅ | ✅ | ✅ |
| Repositories or roots | Edit URL root | ✅ | ✅ | ✅ |
| Repositories or roots | Add exclusions | ❌ | ❌ | ✅ |
| Repositories or roots | Add secrets | ✅ | ✅ | ✅ |
| Repositories or roots | Edit secrets | ✅ | ✅ | ✅ |
| Repositories or roots | Remove secrets | ✅ | ✅ | ✅ |
| Repositories or roots | Add Git environment | ✅ | ✅ | ✅ |
| Repositories or roots | View Git environment | ✅ | ✅ | ✅ |
| Repositories or roots | Edit Git environment | ✅ | ✅ | ✅ |
| Repositories or roots | Delete Git environment | ❌ | ❌ | ✅ |
| Repositories or roots | Move Git environment | ❌ | ❌ | ✅ |
| Vulnerabilities | Vulnerability assignment | ❌ | ✅ | ✅ |
| Vulnerabilities | False positive request | ✅ | ✅ | ✅ |
| Vulnerabilities | Request reattacks | ✅ | ✅ | ✅ |
| Vulnerabilities | Approve treatment | ❌ | ✅ | ✅ |
| Vulnerabilities | Update treatment | ✅ | ✅ | ✅ |
| Vulnerabilities | Add tag | ✅ | ✅ | ✅ |
| Vulnerabilities | Remove tag | ✅ | ✅ | ✅ |
| Vulnerabilities | Post comments | ✅ | ✅ | ✅ |
| Vulnerabilities | View reattack assignees | ❌ | ✅ | ✅ |
| Vulnerabilities | View verification assignee | ❌ | ✅ | ✅ |
| Feature group | Feature | User | Organization Manager |
| Analytics | Download vulnerability report in Analytics | ❌ | ✅ |
| Billing | Add payment method | ❌ | ✅ |
| Billing | Update payment method | ❌ | ✅ |
| Billing | Download billing file | ❌ | ✅ |
| Compliance | Download compliance report | ✅ | ✅ |
| Credentials | Add credentials | ❌ | ✅ |
| Credentials | Update credentials | ❌ | ✅ |
| Credentials | Remove credentials | ❌ | ✅ |
| Credentials | OAuth connection | ❌ | ✅ |
| Members | Add members | ❌ | ✅ |
| Members | View member | ❌ | ✅ |
| Members | Update member | ❌ | ✅ |
| Members | Delete member | ❌ | ✅ |
| Policies | Update org/group policies | ❌ | ✅ |
| Policies | Submit weakness for temporary acceptance in Policies | ✅ | ✅ |
| Policies | Submit weakness for permanent acceptance in Policies | ✅ | ✅ |
| Policies | Approve and reject weakness for temporary acceptance in Policies | ❌ | ✅ |
| Policies | Approve and reject weakness for permanent acceptance in Policies | ❌ | ✅ |
| Policies | Update priority score policies | ✅ | ✅ |
| Project | Add repositories in Outside | ❌ | ✅ |
| Project | Add group | ❌ | ✅ |
| Project | Add organization | ✅ | ✅ |
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan. If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' pentesting team, fill out this contact form.
Members
Efficiently manage organization and group members on the Fluid Attacks platform, including invitations, role assignments, and removals.
Group-level authors
Learn how to view, filter, and manage authors (contributing developers) on the Fluid Attacks platform to enhance collaboration quality and security.