Skip to Content
Getting StartedRoles & permissions

Roles & Permissions

SecureHive uses role-based access control (RBAC) to ensure team members see only what they need. Roles can be assigned manually or synced automatically via SCIM group mapping.

Built-in Roles

RoleAccess Level
OwnerFull access to all features, settings, billing, and user management
AdminFull feature access, user management, no billing access
Security ManagerAll operational planes, no settings or user management
AuditorRead-only access to risk, compliance, and audit modules
AnalystRisk register, vulnerability management, and reporting
ViewerRead-only dashboards and reports

Custom Roles

Create custom roles under Settings → Roles & Permissions to match your organization’s structure. Custom roles allow granular control over:

  • Plane access — Which operational planes a role can see
  • Module permissions — Read, write, delete, and approve within each module
  • Data scope — Filter visibility by business unit, region, or team
  • Export controls — Whether a role can export data or generate reports

SCIM Group Mapping

When SCIM is configured, map your IdP groups to SecureHive roles:

Azure AD Group → SecureHive Role ───────────────────────────────────────── SH-Admins → Admin SH-Security-Team → Security Manager SH-Auditors → Auditor SH-Leadership → Viewer

Group mappings are configured under Settings → Identity & Access → Group Mapping.

Last updated on