Skip to main content
Every person you invite to help manage your Hackrate programs gets exactly one role at a given scope. The role defines what they can do; the scope defines where that permission applies. Getting this combination right means your triage team can work efficiently without accidentally exposing sensitive reports to people who shouldn’t see them — and it means you can bring in an external stakeholder for a single report without giving them access to your entire program.

The Four Roles

Hackrate has four roles, ordered from most to least privileged:

SuperAdmin

Full access across every feature. A SuperAdmin can see all report statuses — including Pre-submission, New, Needs more info, Duplicate, Invalid, Spam, Out of Scope, and Self-Closed — change any status, award bounties, manage team membership, and alter program settings.

StandardAdmin

Triage and management access. A StandardAdmin can review, comment on, update reports, award bounties, manage program settings, and invite team members within their scope. They work in a filtered view that hides early-stage and rejection statuses, keeping their queue focused on actionable items.

Analytics

Read-only access to analytics dashboards and aggregated report data. Useful for management stakeholders who need visibility into program metrics without interacting with individual reports.

Read-Only

Read-only access to reports within the assigned scope. The user can view report details and comments but cannot take any action or see analytics dashboards.

Role Comparison

The table below shows which actions each role can perform:
StandardAdmins see a focused report queue that omits the following statuses: Pre-submission, New, Needs more info, Duplicate, Invalid, Spam, Out of Scope, and Self-Closed. This keeps their inbox clean and prevents premature triage of reports that have not yet passed initial validation or have already been closed as noise.

Permission Scopes

A role only takes effect within the scope it was assigned to. Hackrate supports four scope levels, from broadest to most narrow:
1

Organization

The role applies to every program under your organization. Use this scope for trusted team members who need to work across all programs — for example, your head of security or a platform-wide analytics user.
2

Program

The role applies only to one specific program and all reports within it. This is the most common scope for triage staff.
3

Business Unit

The role applies only to the subset of targets assigned to a particular Business Unit. For example, a “Mobile Team” Business Unit might contain only your iOS and Android app targets, limiting a triager’s view to those reports only.
4

Report

The role applies to a single report. This is useful for temporarily bringing in a specialist — a developer who owns the affected component, for instance — without exposing the rest of your program.

Role Priority

A user may hold multiple roles if they belong to multiple Admin Groups or have been assigned rights at different scopes. Hackrate always applies the most privileged role a user holds across all their assignments. The priority order is:
  1. SuperAdmin
  2. StandardAdmin
  3. Analytics
  4. Read-Only
For example, if a user is a Read-Only at the organization level but a StandardAdmin on a specific program, they will have StandardAdmin access on that program and Read-Only access everywhere else.

Assigning Roles

1

Go to Organization Management

Navigate to your organization dashboard and open the Team or Organization Management section.
2

Invite or select a member

Click Invite member to add a new person by email, or select an existing member from the list.
3

Choose the role and scope

Select the role you want to assign, then choose whether it applies at the organization level, a specific program, a Business Unit, or a single report.
4

Send the invitation

The invitee receives an email. Until they accept, their invitation appears as Pending in the team list.
For managing teams of people rather than individuals, use Admin Groups instead of assigning roles one person at a time. Any role you assign to a group automatically applies to every member.
Only a SuperAdmin at the organization level can assign the SuperAdmin role to others. Make sure at least two people in your organization hold this role so you are never locked out.