People and access
Users and roles
Add people, pick their role, unlock them, and act as them to see what they see.
| Role | Adds |
|---|---|
| viewer | Read rules, packages and vulnerabilities, review a file, and their own requests. |
| developer | Tokens, requests, withdrawing their own requests, and dependency trees. |
| publisher | Publishing npm and PyPI packages and pushing images under reserved names. Usually a CI account. |
| approver | Rules, rule imports, all requests, request and waiver decisions, kills, and purging packages. |
| admin | Settings, users, every token, traffic, the audit trail, cache purges and backups. |
- Under Add someone, fill in the username, name, email, role and a starting password.
- Click Create the account. They must change the password the first time they sign in.
Row actions
- switch off stops an account without deleting its history. Changing a role, switching off or resetting a password ends that person's sessions.
- unlock clears a lockout. Accounts lock after Bad passwords before a lockout (default 5) for How long a lockout lasts (default 15 minutes).
- reset password sets a new one they must change.
- rename keeps the role, tokens and history.
- impersonate lets you act as a non-admin for up to 30 minutes. A red bar with Stop stays on screen, and the audit trail records every action as "admin as them".
Note
You cannot demote, switch off or delete the last admin, or remove your own admin role.
Passwords and sessions
Settings, Access tab: Shortest allowed password (default 12), lockout settings and Portal idle timeout in minutes (default 60). Passwords need three of lower case, upper case, numbers and symbols, and cannot contain the username or common words.