---
title: "User Roles and Permissions"
description: "Learn about the user roles and associated permissions."
canonical_url: "https://cobalt-io.brainfish.ai/articles/user-roles-and-permissions-oCij6uRrUR"
md_url: "https://cobalt-io.brainfish.ai/articles/user-roles-and-permissions-oCij6uRrUR.md"
---
# User Roles and Permissions

Learn about the user roles and associated permissions.

Depending on your role, you may have access to an organization, specific pentests, or both.

## Pentest Team Member

A Pentest Team Member is a customer (organization) representative during a specific pentest. In the UI, you see this role as “Team Member.”

* A Pentest Team Member does not have to be an Organization Owner or an Organization Member.
* When an Organization Owner [invites a user to an organization](https://cobalt-io.brainfish.ai/en-us/articles/manage-users-e390HqcTEl#h-invite-users), the use\`r also becomes a Pentest Team Member on all pentests of the organization.
  * An Organization Owner can [remove a Pentest Team Member from all pentests](https://cobalt-io.brainfish.ai/en-us/articles/manage-users-e390HqcTEl#h-remove-a-user-from-all-pentests) they collaborate on.
  * Any Pentest Team Member can [add users](https://cobalt-io.brainfish.ai/en-us/articles/manage-pentest-collaborators-2pjt0NS56E#h-add-a-pentest-team-member) to a specific pentest or [remove](https://cobalt-io.brainfish.ai/en-us/articles/manage-pentest-collaborators-2pjt0NS56E#h-remove-a-pentest-team-member) them.

A Pentest Team Member **has access to a specific pentest with the following permissions**:

* View and edit pentest details.
* Manage findings for a pentest.
* [Collaborate on a pentest](https://cobalt-io.brainfish.ai/en-us/articles/collaborate-on-pentests-ILbpm2juqQ) in the Cobalt app and in Slack.
* [Manage users](https://cobalt-io.brainfish.ai/en-us/articles/manage-pentest-collaborators-2pjt0NS56E) for a pentest.
* View pentest activity updates and pentester updates.
* Manage native Jira integrations for a pentest.

A Pentest Team Member has no access to any information related to the organization, unless they’re also an Organization Owner or Member.

### Learn more.

A Pentest Team Member has **no access** to the following pages, unless they’re also an Organization Owner or Member:

* **Assets**
* **Pentests** (except for pentests they collaborate on)
* **Findings**
* **Insights**
* **People**
* **Credits**
* **Integrations**
* **Settings**

## Organization Roles

When a customer starts their journey with Cobalt, we add an Organization Owner who then invites other users. Here is an overview of organization roles and permissions.

## Organization Owner

An Organization Owner is the administrator for a customer organization within the Cobalt app. In the UI, you see this role as “Owner.”

An Organization Owner has the following **permissions**:

* Create [assets](https://cobalt-io.brainfish.ai/en-us/articles/assets-are-what-we-pentest-09RgsvQ7zv) and [pentests](https://cobalt-io.brainfish.ai/en-us/articles/pentests-t8vsKFfrV6), edit assets.
* [Manage users for an organization](https://cobalt-io.brainfish.ai/en-us/articles/manage-users-e390HqcTEl) on the **People** page:
  * Invite and remove users.
  * Switch user roles.
  * View users’ email addresses.
  * Remove Pentest Team Members from all pentests they collaborate on.
* Create, edit, and manage [groups](https://cobalt-io.brainfish.ai/en-us/articles/groups-AFqkqDHbW6).
* Manage security settings for an organization: [two-factor authentication](https://docs.cobalt.io/en-us/articles/account-settings-8tW4UtYkk3?utm_source=brainfish&utm_medium=popup_widget#h-two-factor-authentication) and [SAML](https://cobalt-io.brainfish.ai/en-us/articles/configure-saml-sso-oT8Q3qO09D).
* Enable [co-branded reports](https://cobalt-io.brainfish.ai/en-us/articles/co-branded-reports-ss3J7UUcKN) (for Cobalt partners).
* Manage [integrations](https://cobalt-io.brainfish.ai/en-us/articles/cobalt-integrations-t57LnbF8QD) for an organization.
* Edit the [organization profile](https://cobalt-io.brainfish.ai/en-us/articles/configure-organization-settings-AsPfjIf0Ht).
* View the [credits ledger](https://cobalt-io.brainfish.ai/en-us/articles/track-your-credits-2HS0lqCRFt).
* View the [Insights](https://docs.cobalt.io/en-us/articles/insights-r4Jw78EcgA) page.

An Organization Owner may also be a [Pentest Team Member](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-pentest-team-member).

## Organization Member

An Organization Member is a customer representative who manages pentests and assets for their organization on the Cobalt platform but has less permissions compared to an Organization Owner. In the UI, you see this role as “Member.”

An Organization Member has the following **permissions**:

* Create [assets](https://cobalt-io.brainfish.ai/en-us/articles/assets-are-what-we-pentest-09RgsvQ7zv) and [pentests](https://cobalt-io.brainfish.ai/en-us/articles/pentests-t8vsKFfrV6), edit assets, within group permissions.
* View users and pentest collaborators on the **People** page.
* Manage [integrations](https://cobalt-io.brainfish.ai/en-us/articles/cobalt-integrations-t57LnbF8QD) for an organization.
* Edit the [organization profile](https://cobalt-io.brainfish.ai/en-us/articles/configure-organization-settings-AsPfjIf0Ht).
* View the [credits ledger](https://cobalt-io.brainfish.ai/en-us/articles/track-your-credits-2HS0lqCRFt).
* View the [Insights](https://docs.cobalt.io/en-us/articles/insights-r4Jw78EcgA) page.

An Organization Member may also be a [Pentest Team Member](https://cobalt-io.brainfish.ai/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-pentest-team-member).

## Cobalt Pentesters

When you run pentests using the Cobalt Pentest as a Service (PtaaS) platform, Cobalt pentesters participate in the process. This group includes the following roles:

* Pentester
* Lead
* Coordinator

### **Lead**

Manages the testing team while actively executing the test. Reserved for tests with two or more testers.

### **Coordinator**

Manages the testing effort while actively executing the test. Reserved for Agile Tests or tests involving a single tester.

### **Pentester**

Individual contributor who executes testing under the direction of a Lead or Coordinator; does not manage the team.

## **In-House Pentester**

### **In-House Pentester**

An In-House Pentester is a pentester invited by a customer (organization) to perform In-House pentests on the Cobalt [Pentest Management Platform (PMP)](https://cobalt-io.brainfish.ai/en-us/articles/in-house-pentests-HYNuapVOyk). An In-House Pentester role has the same privileges as a Pentest Team Member, with additional access to pentester functionality.

A customer can invite pentesters from their organization, a third-party company, or both to complete In-House pentests on the Cobalt [Pentest Management Platform (PMP)](https://cobalt-io.brainfish.ai/en-us/articles/in-house-pentests-HYNuapVOyk).

Learn [how to complete an In-House pentest](https://cobalt-io.brainfish.ai/en-us/articles/complete-an-in-house-pentest-for-pentesters-y7RCf5izE6).

## **Cobalt Staff**

Select Cobalt Staff members have administrative access to your organization and tests. If needed, they can help you:

* Manage users in your organization
* Manage work on your tests
