πŸ‘₯ Understanding User Permissions

Learn about the different user permissions in Scaut and how to assign them to your team members.

How access works

In Scaut you grant access by assigning roles. A role is a predefined set of permissions, so assigning a role gives a member everything that role includes in one step. You choose the role when you invite a member, and you can change it later. Your organization can also create and edit its own roles to match how your team is structured.

Roles you can assign

These are the roles exactly as they appear when you invite a member.

RoleWhat it can do
πŸ‘‘ OwnerHas full access (All)
🏒 ManagerCan manage organization information, users, and allowed products (User Management)
πŸ’° FinanceCan set spending limits, view invoices, export transactions, and modify payment methods (Billing Management)
πŸ“¦ ProductCan order products (Place Order)
πŸ” DetailCan view detailed responses (Order Oversight)
βœ… ApproverCan approve responses (includes Detail access automatically)
πŸ‘€ MemberCan sign in and view summary responses (Limited View)
πŸ§ͺ DeveloperCan switch to the sandbox
πŸ”„ Shared ManagerCan manage critical infrastructure information (Organization Share)
πŸ‘οΈ Shared ViewerCan view critical infrastructure information (View Organization Shares)

A few things worth knowing:

  • Owner is the full-access role, normally held by whoever created the organization. Limit it to essential people.
  • Approver includes Detail access automatically, so an approver can view detailed responses as well as approve them.
  • Developer gives access to the sandbox, the environment for testing.
  • Shared Manager and Shared Viewer govern information shared with connected organizations.

Inviting a member

  1. In Organization Settings, open the Users tab and choose to invite a new member.
  2. Enter the person's email address.
  3. Select the role to assign.
  4. Click Send Invite. The person receives an email invitation to join your organization.

If you would rather share an invitation without sending it by email, use Generate invite code for manual sharing and pass the code to the person directly.

Changing a member's role

  1. Go to Organization Settings, then Users.
  2. Find the user in the list.
  3. Open their options and choose to edit.
  4. Add or change the role as needed.
  5. Save your changes.

Viewing current users

In the Users tab you can see the full list of organization users, the role each one holds, their status (active or inactive), and last login information.

Choosing the right role

  • Places orders only: Product.
  • Reviews full screening results: Detail.
  • Approves results, and needs to see the detail to do so: Approver.
  • Runs the organization, its users, and allowed products: Manager.
  • Handles spending limits, invoices, and payment methods: Finance.
  • Just needs to sign in and see summaries: Member.
  • A technical user working in the sandbox: Developer.
  • Works with connected organizations on shared information: Shared Manager to manage, Shared Viewer to view.

Restricting visibility in Governance settings

In your Governance settings you can restrict users who place orders or view results so they see only their own, rather than everything across the organization. Owners, who have full access, always see all checks and results.

Best practices

  • Apply the principle of least privilege: give the minimum access each person needs.
  • Limit the Owner role to essential personnel only.
  • Separate ordering (Product) from full visibility (Detail) where you can.
  • Review roles on a regular schedule, for example quarterly.
  • Keep a record of who holds which role, and why.

Troubleshooting

A user cannot access a feature they expect

  • Verify the correct role is assigned.
  • Confirm the role actually covers the action they are trying to take.
  • Make sure the user has accepted the invitation.
  • Confirm the user is in the correct organization.

You need to change several users' roles

  • Review each user individually.
  • Record the changes you make.
  • Tell the affected users what changed.

πŸ’‘ Tip: map your job titles to the Scaut role each one needs, and keep that mapping somewhere your team can find it. It keeps onboarding consistent and makes regular access reviews much quicker.