Roles
HoundER has two customer-facing roles. Every user in your organization is assigned one of them.
- Organization Admin — full access across the entire organization: every project, plus organization-level administration (settings, users, API keys).
- Project Admin — admin access scoped to the specific projects they're assigned to. They can't see or manage projects they aren't assigned to, and have no access to organization-level administration.
Permissions matrix
| Resource | Organization Admin | Project Admin |
|---|---|---|
| Projects — view | All projects | Assigned projects only |
| Projects — create / delete | Yes | No |
| Projects — edit | Yes | Assigned projects only |
| Assets — view | All projects | Assigned projects only |
| Assets — create / edit / delete | Yes | Assigned projects only |
| Scans — view / launch / manage | Yes | Yes, on assigned projects |
| Agents — view / connect / manage | Yes | Yes, on assigned projects |
| Workflows — view / create / edit / delete | Yes, all projects | Yes, on assigned projects |
| Findings — view | All projects | Assigned projects only |
| Findings — triage (update status, add comments) | Yes | Yes, on assigned projects |
| Findings — delete a comment | Any comment | Own comments only |
| Reports — view / download | All projects | Assigned projects only |
| Reports — create / edit / delete | Yes | Assigned projects only |
| Organization Settings | Yes | No |
| Users | Yes | No |
| API Keys | Yes | No |
Findings triage — updating a vulnerability or credential's status, or adding a comment — isn't restricted to admins; any authenticated user with access to a project can triage findings within it. Deleting someone else's comment, however, requires Organization Admin.