User Roles and Permissions
Learn about the user roles and associated permissions.
Depending on your role, you may have access to an organization, specific pentests, or both.
Pentest Team Member
A Pentest Team Member is a customer (organization) representative during a specific pentest. In the UI, you see this role as “Team Member.”
- A Pentest Team Member does not have to be an Organization Owner or an Organization Member.
- When an Organization Owner invites a user to an organization, the use`r also becomes a Pentest Team Member on all pentests of the organization.
- An Organization Owner can remove a Pentest Team Member from all pentests they collaborate on.
- Any Pentest Team Member can add users to a specific pentest or remove them.
A Pentest Team Member has access to a specific pentest with the following permissions:
- View and edit pentest details.
- Manage findings for a pentest.
- Collaborate on a pentest in the Cobalt app and in Slack.
- Manage users for a pentest.
- View pentest activity updates and pentester updates.
- Manage native Jira integrations for a pentest.
A Pentest Team Member has no access to any information related to the organization, unless they’re also an Organization Owner or Member.
Learn more.
A Pentest Team Member has no access to the following pages, unless they’re also an Organization Owner or Member:
- Assets
- Pentests (except for pentests they collaborate on)
- Findings
- Insights
- People
- Credits
- Integrations
- Settings
Organization Roles
When a customer starts their journey with Cobalt, we add an Organization Owner who then invites other users. Here is an overview of organization roles and permissions.
Organization Owner
An Organization Owner is the administrator for a customer organization within the Cobalt app. In the UI, you see this role as “Owner.”
An Organization Owner has the following permissions:
- Create assets and pentests, edit assets.
- Manage users for an organization on the People page:
- Invite and remove users.
- Switch user roles.
- View users’ email addresses.
- Remove Pentest Team Members from all pentests they collaborate on.
- Create, edit, and manage groups.
- Manage security settings for an organization: two-factor authentication and SAML.
- Enable co-branded reports (for Cobalt partners).
- Manage integrations for an organization.
- Edit the organization profile.
- View the credits ledger.
- View the Insights page.
An Organization Owner may also be a Pentest Team Member.
Organization Member
An Organization Member is a customer representative who manages pentests and assets for their organization on the Cobalt platform but has less permissions compared to an Organization Owner. In the UI, you see this role as “Member.”
An Organization Member has the following permissions:
- Create assets and pentests, edit assets, within group permissions.
- View users and pentest collaborators on the People page.
- Manage integrations for an organization.
- Edit the organization profile.
- View the credits ledger.
- View the Insights page.
An Organization Member may also be a Pentest Team Member.
Cobalt Pentesters
When you run pentests using the Cobalt Pentest as a Service (PtaaS) platform, Cobalt pentesters participate in the process. This group includes the following roles:
- Pentester
- Lead
- Coordinator
Lead
Manages the testing team while actively executing the test. Reserved for tests with two or more testers.
Coordinator
Manages the testing effort while actively executing the test. Reserved for Agile Tests or tests involving a single tester.
Pentester
Individual contributor who executes testing under the direction of a Lead or Coordinator; does not manage the team.
In-House Pentester
In-House Pentester
An In-House Pentester is a pentester invited by a customer (organization) to perform In-House pentests on the Cobalt Pentest Management Platform (PMP). An In-House Pentester role has the same privileges as a Pentest Team Member, with additional access to pentester functionality.
A customer can invite pentesters from their organization, a third-party company, or both to complete In-House pentests on the Cobalt Pentest Management Platform (PMP).
Learn how to complete an In-House pentest.
Cobalt Staff
Select Cobalt Staff members have administrative access to your organization and tests. If needed, they can help you:
- Manage users in your organization
- Manage work on your tests
