User Management
Introduction​
Conviso Platform allows you to manage users, groups and roles to ensure the proper information and authorization is given for the right people.
Description​
There are types of Users that are categorized according to the type of permission, called Profiles and it is possible to group them into Teams.
About Users​
Conviso Platform users are all those who have access to the platform and are linked to an email and one or more companies. They are created through the Invite New Users action and can be managed in Access Control.
Users have different levels of permissions, and are defined in Profiles.
About Profiles​
Profiles are predefined sets of permissions that determine what a user can do on the system. Each profile is created for a specific role or function within the organization and is composed of a set of permissions that define which features and functionality of the system the user will have access to.
Custom profiles​
Custom profiles are created by administrators and allow you to define access permissions according to the organization's needs.
There are more resources to come in the following releases so you can make a more granular configuration of your custom profiles.
Default Profiles​
On the Platform, there are 3 default profiles:
Developer Profile​
Profile Developer was created with the aim of streamlining the platform for software engineers, so that they only have access to what is relevant to their work. Permissions:
- Limited vulnerability status update (False Positive and Risk Accepted are not allowed);
- Create, view, and edit Assets;
- Create, view, and edit Projects.
To add new users with Developer Profile roles, see here how to invite new users.
Admin Profile​
The Admin profile is designed to provide full access to all the functionalities of the company's platform to which they belong, in addition to the following exclusive accesses:
- Full access to Access Control:
- Management of users in their account;
- Profile management;
- Team management ;
- Business unit management.
Viewer-only​
The Viewer-Only profile, a global Profile, refers to users who only have permission to view what was assigned to them on the platform by the administrator.