---
title: Roles and permissions
description: The three tenant roles in Advisor, the capabilities of each one and the permissions outside the default roles.
updated: 2026-09-27
---

Access in Advisor is granted by role within each tenant. A user can have different roles in different tenants. Menu items show up according to the role's permissions. An address opened without permission shows an access-denied screen.

## Tenant roles

| Role | For whom |
|---|---|
| **Tenant Admin** | Setting up and operating Advisor for the customer: connection, members, SSO, risks, spikes and responses. |
| **Tenant Manager** | Access administration: viewing and managing members and invites. |
| **Tenant User** | Monitoring: viewing posture, metrics, incidents and responses, without permission to change them. |

Roles are assigned in **Administração** (Administration) > **Membros** (Members).

## What each role can do

| Capability | Permission | Tenant Admin | Tenant Manager | Tenant User |
|---|---|:---:|:---:|:---:|
| See Overview, Risks, Inventory, Evolution, Cloudflare and Integrations | `connections.read` | Yes | No | Yes |
| Add, edit or delete the connection | `connections.write` | Yes | No | No |
| Accept and restore risks | `posture.ignores.write` | Yes | No | No |
| Delete a zone already removed in Cloudflare | `connections.zones.delete` | Yes | No | No |
| See members | `tenants.members.read` | Yes | Yes | No |
| Invite, change roles and remove members | `tenants.members.write` | Yes | Yes | No |
| Set up SSO | `tenants.sso.manage` | Yes | No | No |
| Make two-step verification mandatory | `tenants.security.manage` | Yes | No | No |
| See the tenant audit trail | `audit.read` | Yes | No | No |
| See spike rules and incidents | `spikes.rules.read`, `spikes.incidents.read` | Yes | No | Yes |
| Create and edit rules; resolve, ignore and reopen incidents | `spikes.rules.write` | Yes | No | No |
| See responses, analyses and the knowledge base | `responder.read` | Yes | No | Yes |
| Approve, reject and run actions; reanalyze | `responder.actions.execute` | Yes | No | No |
| Edit playbooks | `responder.playbooks.write` | Yes | No | No |
| Edit the knowledge base | `responder.knowledge.write` | Yes | No | No |
| See notification destinations | `notifications.read` | Yes | No | Yes |
| Create and edit notification destinations | `notifications.write` | Yes | No | No |
| See domain expiry | `domains.expiry.read` | Yes | No | Yes |
| Set up expiry warnings | `domains.expiry.write` | Yes | No | No |

## Permissions outside the default roles

Some features are not included in any tenant role. To get access, contact Guardnet.

| Feature | Permission |
|---|---|
| **Sincronizar** (manual sync) and **Sincronizar alterações** (Sync changes) | `connections.scan` |
| **Recalcular** (Recalculate) a zone's score | `posture.rules.write` |
| **Ao Vivo** (Live) menu, the request map | `map.read` |
| **Origem do mapa** (Map origin) | `map.write` |

:::note
Without manual sync, data refreshes on the scheduled collection, every day at 02:00 (Brasília time). Refer to [Connections and sync](/en/advisor/conceitos/conexoes-e-sincronizacao/).
:::

---

> Guardnet Docs · https://docs.guardnet.com.br/en/advisor/referencia/papeis-e-permissoes/
> Documentation index: https://docs.guardnet.com.br/en/llms.txt
