The Four Roles
Hackrate has four roles, ordered from most to least privileged:SuperAdmin
Full access across every feature. A SuperAdmin can see all report statuses — including Pre-submission, New, Needs more info, Duplicate, Invalid, Spam, Out of Scope, and Self-Closed — change any status, award bounties, manage team membership, and alter program settings.
StandardAdmin
Triage and management access. A StandardAdmin can review, comment on, update reports, award bounties, manage program settings, and invite team members within their scope. They work in a filtered view that hides early-stage and rejection statuses, keeping their queue focused on actionable items.
Analytics
Read-only access to analytics dashboards and aggregated report data. Useful for management stakeholders who need visibility into program metrics without interacting with individual reports.
Read-Only
Read-only access to reports within the assigned scope. The user can view report details and comments but cannot take any action or see analytics dashboards.
Role Comparison
The table below shows which actions each role can perform:StandardAdmins see a focused report queue that omits the following statuses: Pre-submission, New, Needs more info, Duplicate, Invalid, Spam, Out of Scope, and Self-Closed. This keeps their inbox clean and prevents premature triage of reports that have not yet passed initial validation or have already been closed as noise.
Permission Scopes
A role only takes effect within the scope it was assigned to. Hackrate supports four scope levels, from broadest to most narrow:1
Organization
The role applies to every program under your organization. Use this scope for trusted team members who need to work across all programs — for example, your head of security or a platform-wide analytics user.
2
Program
The role applies only to one specific program and all reports within it. This is the most common scope for triage staff.
3
Business Unit
The role applies only to the subset of targets assigned to a particular Business Unit. For example, a “Mobile Team” Business Unit might contain only your iOS and Android app targets, limiting a triager’s view to those reports only.
4
Report
The role applies to a single report. This is useful for temporarily bringing in a specialist — a developer who owns the affected component, for instance — without exposing the rest of your program.
Role Priority
A user may hold multiple roles if they belong to multiple Admin Groups or have been assigned rights at different scopes. Hackrate always applies the most privileged role a user holds across all their assignments. The priority order is:- SuperAdmin
- StandardAdmin
- Analytics
- Read-Only
Assigning Roles
1
Go to Organization Management
Navigate to your organization dashboard and open the Team or Organization Management section.
2
Invite or select a member
Click Invite member to add a new person by email, or select an existing member from the list.
3
Choose the role and scope
Select the role you want to assign, then choose whether it applies at the organization level, a specific program, a Business Unit, or a single report.
4
Send the invitation
The invitee receives an email. Until they accept, their invitation appears as Pending in the team list.