Roles and permissions
NoCert has three roles. Every member has exactly one.
| Role | What they can do |
|---|---|
| Viewer | Read-only on the dashboard, certificates, endpoints and compliance, plus their own profile. No Domains, Sentinels, Connectors, Notification Rules or Targets, and no Activity. |
| Operator | Everything about monitoring: domains, Sentinels, endpoints, connectors, rules, targets, muting, accepting a compliance risk. |
| Owner | Everything an operator can, plus members, billing, single sign-on, organization settings, the organization-wide scan configuration and the active compliance policies. |
A screen a role cannot use is absent from the sidebar, and its URL redirects to the dashboard.
Roles need Business
Section titled “Roles need Business”On Pro, everyone you add is an operator. The role picker and viewer scoping appear once you are on Business.
That makes Pro an organization where everybody can change everything, which is fine for a small team and worth knowing before you invite someone outside it.
One exception, and it is a common one: the trial is a Business trial. Viewers and tag scopes you set up during it keep working after you settle on Pro. Only new assignments are refused.
Restricting a viewer to part of the estate
Section titled “Restricting a viewer to part of the estate”On Business you can tie a viewer to endpoint tags. They then see only the certificates and endpoints carrying those tags, everywhere: lists, dashboard, compliance and exports all follow the same scope.
Scoped viewers lose a couple of aggregate views. The compliance trend chart is unavailable to them on every plan, since it is an organization-wide series with no per-scope version, and on a plan without the Business detail their severity counts are hidden too: a precise number over a small scope identifies the asset it refers to.
Adding someone
Section titled “Adding someone”Owners add members from Settings → Local Users.
NoCert creates the account and shows you a temporary password once. There is no invitation email: you copy that password and pass it to the person yourself, through whatever channel you trust. They are forced to choose their own password at first sign-in.
No password appears when single sign-on is enforced and the address is on your SSO domain. That person signs in through your provider and has no local credential to hand over.
Pro allows ten local accounts, Business twenty. Members provisioned by your identity provider do not count against either.
Owners
Section titled “Owners”The person who signed up is the owner. There is no ownership transfer in the app, and no way to promote someone to owner from the members screen.
The one path that creates a second owner is a single sign-on group mapped to the owner role, which is a Business feature.