Organisation roles
Every user belongs to an organisation with one of these roles:What each role can do
Workspace access
Workspaces have their own access layer that determines who can view and modify the threat models within them.Workspace types
Access types
Shared and repository workspaces have a configurable access type:Workspace permissions
Within a shared or repository workspace, permissions depend on your relationship to the workspace:Threat model access
Access to threat models is inherited from workspaces. If you can access any workspace that contains a threat model, you can view and update it. Security requirements inherit access from their parent threat model.A threat model can belong to multiple workspaces. A user only needs access to one of those workspaces to view and edit the threat model.
How roles are assigned
- Organisation role — Set by an existing org admin via the organisation settings. New members join as Org Member by default.
- Workspace membership — Added by the workspace owner, an existing workspace member, or an org admin.
- Workspace ownership — The user who creates the workspace becomes its owner. Ownership can be transferred by the current owner or an org admin.
Workspaces
Learn about creating and configuring workspaces.