Two independent levels of roles
Permissions in the multi-tenancy model are designed around a simple principle: administering the structure and seeing the security data are two separate things. That's what lets you delegate tenant administration without handing out access to sensitive findings.
They work on two distinct, independent levels:
Organization roles - users with these roles con perform actions inside an organization (Auditor, Standard, Organization admin).
Tenant role - users with this role are able to access the Tenant space, the central space managing the tenant and its organizations.
These two levels are completely separate. A user's Tenant role has no bearing on their organization role, and vice versa. A user can have:
an organization role only,
a Tenant role only,
or both at the same time.
Each is granted separately, so there's no automatic link between being a Tenant admin and holding any particular role inside an organization.
Organization roles
Users are assigned one of the following roles in the organizations they can access:
Auditor
Standard
Organization admin
Good to know: for now, a user keeps the same role across all their organizations. If someone has access to several organizations, that single role applies in each of them. The ability to assign a different role per organization is on the roadmap for a future release.
Tenant role
To access the Tenant space — the management area for your tenant — a user needs the Tenant admin Tenant role.
Holding it changes nothing about what a user can do inside an organization, and the reverse holds too: being an Organization admin, even in every organization, never grants access to the Tenant space by itself. Tenant-level administration and what happens inside each organization stay cleanly separated.
Tenant admin without an organization
Because the two levels are independent, it is possible to add a user as a Tenant admin without assigning them to any organization.
In that case, the user:
can access only the Tenant space, by logging in to the Dashboard,
and therefore does not have access to the confidential content of any organization (assets, scans, results, etc.).
This is the right setup when someone needs to administer the tenant structure — creating organizations, allocating resources, and so on — without needing (or being allowed) to see the security data inside each organization.


