Access
Who can see what
| Member | Role | Can reveal addresses | Can export |
|---|---|---|---|
| No members yet. | |||
Recent audit events
No audit events yet.
Permission model
Every route checks the organisation boundary before the role, so an Analyst on one tenant cannot read another's findings even with a valid token. Reveal and export are separate permissions from view.
identity:viewidentity:revealfinding:updatefinding:assigndomain:verifymember:invitereport:exportaudit:view