Users & access

Role-based access with optional account-scoped and tag-scoped permissions. MFA is mandatory. SSO on Enterprise.

Users (8)

UserRoleMFAScopeLast login
[email protected]OwnerTOTPallnow
[email protected]AdminTOTPall12m ago
[email protected]ViewerTOTPtag env=prod, Cost pillar only1h ago
[email protected]ViewerWebAuthnaccount security, read-only, 7-yr audityesterday
[email protected]MemberTOTPaccounts sandbox, staging2d ago
[email protected]MemberTOTPaccounts sandbox, staging3d ago
[email protected]AdminTOTPSecurity pillar only4h ago
[email protected]ViewerTOTPdashboards + reports1d ago

Roles

RoleCapabilities
Ownerbilling + everything
Adminconnectors + settings + findings triage + reports
Memberfindings triage (scoped) + reports (scoped)
Viewerread-only (scoped)

Custom roles available on Enterprise.

SSO & SCIM

Enterprise only. SAML 2.0 or OIDC with JIT account creation. SCIM 2.0 for user and group provisioning.

Enterprise upgrade required. pricing.

Configure SSO →

Recent audit events

Time (UTC)ActorEventTarget
2026-04-16 04:12systemconnector.sync.completedAWS prod-us-east-1
2026-04-16 03:44[email protected]auth.login.success.
2026-04-15 22:02[email protected]connector.createAzure acme-data
2026-04-15 18:10[email protected]finding.exception.createaws.rds.public-subnet
2026-04-15 09:00systemreport.generate.successCost deep dive · GCP

Retention: 30 days (Free) / 1 year (Pro) / 7 years with S3 Object Lock export (Enterprise).