Skip to main content

Pentest Permissions

Organizations: Grant permissions to your pentest members

Updated this week

Overview

Grant permissions to your engagement members by assigning them to a group with the appropriate permissions.

You can assign multiple roles per group and multiple groups per user. Groups allow you to set up your teams and grant the right team permissions to the various areas on the platform. HackerOne Organization administrators can set these access rights for groups on your program.

Below are the available roles with the permissions granted to each.

Roles

Each role has its own permissions. You can assign multiple roles to each group if you want to combine permissions.

Organization Admin

  • Manage engagements

  • Assign permissions

Program Admin

  • Complete the self-setup form

  • Read reports

  • Write internal comments

Report Manager

  • Read reports

  • Write public comments

  • Request retests

Read Only

  • Read reports

Adding a New Group

To add a new group and set access rights:

  1. Go to Organization Settings > Groups.

  2. Click Add new group.

  3. Write the name of the group in the Group name field.

  4. Fill out the three optional fields as desired

    • Organization access and permissions

    • Engagements and reports permissions

    • Asset access and permissions

  5. Select the permissions you want to enable for the group and click Add group in the bottom right-hand corner.

Adding & Removing Users

To add or remove users from a group:

  1. Go to Organization settings > Groups

  2. Click the kabob menu (three vertical dots) next to the group you are adding a member to

  3. Click Edit group

  4. Click Add another user to add a new member
    OR
    Click the trash icon to the right to remove a user from the group

You can also edit the groups an individual is part of:

  1. Go to Organization settings > Users

  2. Search for the user

  3. Click the user’s name

  4. Go to the Groups tab

  5. Click Manage groups for this user

  6. Use the dropdown to add or remove groups, then click Save.

Did this answer your question?