Skip to main content
The Members section (under Settings → Members) lets you manage who can access a workspace and what they can do inside it. Its subtitle summarizes the scope: “Manage members, invitations and permission groups”. Membership is workspace-scoped. A platform user becomes a member of a workspace through an invitation, and every member is assigned a permission group that defines their capabilities.

Key concepts

Members

Members are the people who work inside a workspace. Each member row shows the Member and their Permission — for example, a member named AD Admin with permission Owner, or a member named DE demo1 with permission Read only.

Invitations

Invitations are how new members join a workspace. A pending invitation grants no access until it is accepted.

Permission groups

Permission groups bundle a set of permissions under one name. Assigning a group to a member grants exactly the permissions the group contains.

The Members screen

The screen has three tabs:

Invite a member

1

Open the Members tab

Navigate to Settings → Members.
2

Click Invite member

The Invite member button opens the invitation form.
3

Enter the email address(es)

Provide one or more email addresses for the people you want to invite.
4

Choose a permission group

Select the permission group the new members should receive.
5

Send the invitation

Submit the form. An invitation is sent to each address; it appears under the Invitations tab until accepted.
Once an invitee accepts, they appear in the Members tab with the permission group you selected. Use the per-row menu to change a member’s permission or remove them at any time.
Yes. Open the Invitations tab to see all pending invitations. Each pending invite can be resent (for example, if the email was lost) or cancelled (to revoke the invite before it is accepted).

Manage members

In the Members tab, each row has a menu with two actions:
  • Change permission — re-assign the member to another permission group.
  • Remove — remove the member from the workspace. Removed members lose access immediately.

Create a permission group

1

Open the Permissions tab

Navigate to Settings → Members → Permissions.
2

Search or browse

Use the Search permission groups… box to find existing groups.
3

Click Create group

The Create group button opens the group editor.
4

Name the group and select permissions

Give the group a name and choose the permissions it grants.
5

Save the group

Submit the form. The group is now available when inviting members or changing permissions.

Built-in permission groups

OASM ships with three built-in groups. In practice, the Admin group can view and update workspace information, change workspace configuration, manage the workspace API key, add or remove members, manage invitations, create and modify workflows and permission groups, and view and modify scan targets. The Read only group is limited to viewing invitations and discovered assets.

Best practices

  • Start every member with the least privilege they need and escalate only when required.
  • Reserve Owner System and Admin for a small set of trusted members — these groups can delete the workspace and manage its configuration.
  • Create dedicated groups for recurring team roles instead of assigning permissions ad hoc.
  • Review pending invitations and members regularly; cancel stale invites and remove members who left.
  • Keep the workspace Read only group for members who only need to monitor results.

Users and roles

Understand platform roles such as admin, user, and bot

Workspace

Understand the isolated tenant members operate in

API keys

Manage the workspace API key for programmatic access

Audit log

Review membership and invitation activity