Skip to content

Roles & Permissions ​

Hashiro checks role permissions and organization scope independently. Every user has one organization role; project membership adds the corresponding project access.

Roles ​

Platform administrator ​

administrator is reserved for Hashiro platform staff. Global operations require both the reserved staff license and the relevant Administration permission.

Manager ​

manager administers the provider or client's own organization, team, templates, and authorized projects. It does not grant global administration.

Pentester ​

pentester works within explicitly assigned projects. Read and write capabilities depend on the permissions assigned inside the project.

Hunter ​

hunter supports independent research and bug bounty workflows within its license and permitted project and template access.

Viewer ​

viewer reads explicitly assigned projects without management permissions.

Permission model ​

Permissions use domain-specific Create, List, Update, and Delete capabilities. Projects also use AllProjects and project membership.

DomainExamples
ProjectsScope, members, and details
AssetsInventory, URLs, and services
FindingsDocumentation, severity, and status
TemplatesFinding and report models
UsersInvitations, roles, and removal
OrganizationSettings, integrations, and logo
AI AssessmentsAuthorized runs and configuration

All projects ​

AllProjects allows access to authorized projects without individual membership. Managers have this capability; pentesters and viewers require explicit membership.

Providers and clients ​

The organization's license determines data scope. Providers can access their own organization and linked clients where the operation permits it. Clients are confined to their own organization. The same role does not imply the same data scope.

Provider-managed projects keep configuration writes under provider control. Client-managed projects allow the client's own authorized team to manage the assessment.

Role selection

Use Manager for organization administration, Pentester for assessment work in assigned projects, and Viewer for stakeholders who need to read results. Check project permissions as well as the organization role.

Hashiro. Continuous Threat Exposure Management.