Skip to main content

Choose the Right Role

Gecko has four built-in team roles:
  • Admin
  • Manager
  • Member
  • Read Only
Pick the narrowest role that still lets the person do their job. That keeps team settings safe without slowing down day-to-day scanning and remediation.

Who Should Get Each Role

1

Use Admin for team owners

Give Admin to the people who manage team settings, authentication, roles, and broad platform configuration.
2

Use Manager for day-to-day security operations

Manager is the best fit for people who run scans, manage repositories, tune workflows, and handle remediation without owning identity or team administration.
3

Use Member for normal scan and remediation work

Member can run scans and work findings, but does not manage SSO, roles, or repository configuration.
4

Use Read Only for visibility without mutation

Read Only works for stakeholders who need access to scan results, settings, and audit data without changing the team state.

What Each Role Can Do

Admin

Full access across team settings, members, roles, identity, repositories, scans, findings, integrations, and API keys.

Manager

Manages the working security program: repositories, scans, findings, schedules, workflows, rules, and integrations.

Member

Runs scans, reviews findings, and helps fix issues, but cannot manage team configuration, repositories, roles, or SSO.

Read Only

Sees the platform, findings, settings, and audit information without making changes.

Permission Matrix

Use this table when you need to decide who should be able to manage something versus only view it.
ResourceAdminManagerMemberRead Only
Team SettingsManageViewViewView
MembersManageViewViewView
RolesManageViewViewView
SSO / SCIMManageViewNo AccessView
RepositoriesManageManageViewView
ScansManageManageManageView
FindingsManageManageManageView
RulesManageManageViewView
SchedulesManageManageViewView
WorkflowsManageManageViewView
IntegrationsManageManageViewView
API KeysManageViewViewNo Access
Audit LogViewViewViewView