Back to Home

Enterprise Role-Based Access Control (RBAC)

Manage large security teams securely. Enforce least-privilege access with granular permission matrices.

Security Built for Teams

In a large organization, sharing a single login credential for your security tooling is a massive compliance violation. FortPilot provides enterprise-grade identity and access management for your entire SecOps team.

Implement strict Role-Based Access Control (RBAC). Allow your compliance team to view and export reports (Viewer), allow QA engineers to trigger scans (Analyst), but restrict API key generation, billing, and destructive actions solely to management (Admin).

What is Role-Based Access Control (RBAC)?

RBAC is a security paradigm where system access is strictly restricted to authorized users based on their role within an enterprise. It ensures that employees only have access to the exact tools they need to perform their jobs—nothing more, nothing less.

Core Roles Supported

Organization Admins

Full control over the workspace. Admins can invite or revoke users, manage billing, generate API tokens, and configure global webhook integrations.

Security Analysts

The operational layer. Analysts can configure targets, initiate vulnerability scans, validate false positives, and access the raw JSON payloads for remediation.

Report Viewers

Designed for compliance officers, external auditors, or executive stakeholders. Viewers have read-only access to dashboards and PDF reports, but cannot trigger new scans or alter configurations.

How to Configure Team Access

  1. Navigate to Settings: Go to the Team & Access tab in your FortPilot dashboard.
  2. Invite Members: Enter the email addresses of your team members.
  3. Assign Roles: Select the appropriate role (Admin, Analyst, Viewer) from the dropdown.
  4. Audit Logs: Monitor the activity log to ensure users are operating within their permitted scope.

RBAC & Collaboration FAQ

Does FortPilot support SSO (Single Sign-On)?

Yes. Enterprise tier customers can integrate FortPilot directly with their SAML/OIDC identity providers like Okta, Azure AD, or Google Workspace.

Can I create custom roles?

Custom role creation with granular endpoint-level permissions is available exclusively on our custom Enterprise plans.

Is user activity logged?

Yes, every action (from initiating a scan to deleting a target) is indelibly recorded in the organization's audit log with a timestamp and IP address.

Key Capabilities

Granular Standard Roles

Out-of-the-box support for Admin, Analyst, and Viewer permission sets to cover standard team topologies.

Comprehensive Audit Logging

Track exactly which user triggered a scan, modified a configuration, or exported a report.

SSO & SAML Integration

Seamlessly authenticate users via Okta, Microsoft Entra ID (Azure AD), and Google Workspace.

Least-Privilege Enforcement

Ensure engineers cannot accidentally delete historical audit data or modify billing details.

MFA Enforcement

Force all users within your organization to enable Multi-Factor Authentication before logging in.

Project-Level Scoping

Restrict specific Analysts so they can only view and scan projects assigned to their specific business unit.