Security & Access
Inviting your security team and assigning roles
CybAura is built for teams. This guide covers inviting members and assigning the right level of access using role-based access control (RBAC).
Inviting a member
- Go to Settings → Users & Roles.
- Select Invite user and enter their work email.
- Choose a role (see below).
- Send the invitation. They'll receive an email to set up their account. If SSO is enforced, they'll sign in through your identity provider instead.
Roles
CybAura includes these built-in roles:
- Tenant Admin — full access, including billing, users, and security settings.
- Security Manager — manages risks, controls, agents, and incidents, but not billing or user administration.
- Analyst — works day-to-day across modules; can act on findings and evidence.
- Auditor / Read-only — can view and export, but cannot make changes. Ideal for external auditors.
Assign the least privilege necessary for each person's job.
Changing or removing access
- Update a member's role at any time from Settings → Users & Roles.
- Deactivate a member to immediately revoke access while preserving their history and audit trail.
- If you use SCIM provisioning, deactivating a user in your identity provider deactivates them here automatically.
Ownership and routing
Many items in CybAura — risks, controls, agent escalations — have an owner. Assigning owners ensures notifications and tasks reach the right person rather than a shared inbox.
Audit trail
Every access change is recorded under Settings → Audit Log, which is useful evidence for SOC 2 and ISO 27001 access reviews.
Tip: Run a periodic access review — confirm each member still needs their role. CybAura can remind you on a schedule under your compliance calendar.
Still stuck? Email support@cybaura.io or use the in-app chat.