Skip to content

Developer portal

Dashboard team, invites, and roles

Tenant admins manage people under Settings → Team members. Roles apply to WorkOS dashboard sign-in, not automation API keys.

Last updated: 2026-06-14

Roles at a glance

RoleTypical useDashboard access
adminWorkspace owner, IT or security leadFull settings, team, API keys, SSO, all tabs and exports
operatorEngineers running scans and remediationScans, monitor, remediate; no team or key admin
viewerExecutives, auditors, read-only stakeholdersOverview and scans; compliance widgets; PDF exports only

Backend APIs enforce the same boundaries. The UI hides tabs and widgets using tenant role policies (see below).

Who can manage the team

Only users with the admin role see the full Team members panel under Settings. Operators and viewers see a notice that admin role is required. Your role appears in the workspace header and in GET /api/dashboard/me → session.role and capabilities.

Inviting a teammate

  1. Sign in at qtangl.com/dashboard as an admin.
  2. Open the Settings tab.
  3. Scroll to Team members.
  4. Enter the colleague's work email and choose a role (default: operator).
  5. Click Send invite — WorkOS emails a sign-in link.

After the invitee signs in, Qtangl links them to your tenant with the role you selected. Admins can change roles with the dropdown next to each member, or use Remove to revoke access. Pending invites can be cancelled with Revoke.

Capabilities by role

Computed server-side on login via GET /api/dashboard/me:

  • canAdmin — settings, team, SSO, audit (admin only)
  • canWrite — run scans, remediation (admin + operator)
  • canViewCompliance — all three roles
  • canManageKeys — automation API keys (admin only)
  • canInvite — send team invites (admin only, Monitor tier+)

Dashboard visibility (role policies)

Tenant settings include rolePolicies that filter tabs, widgets, and export formats in the UI. Defaults:

  • viewer — Overview and Scans tabs; PDF exports
  • operator — Overview, Scans, Monitor, Remediate; PDF, board, bundle exports
  • admin — all tabs and export formats

Admins can override defaults via PATCH /tenant/settings with a rolePolicies object. There is no Settings form for this yet — contact Qtangl support or use the API for customizations. The persona toggle (Operator vs Executive in the header) adjusts layout emphasis only; it does not change security boundaries.

Automation API keys (not human login)

Under Settings → Automation API keys (admin only), create keys for CI, Terraform, and scripts. Each key has its own role. Secrets are shown once at creation. Humans should sign in with WorkOS, not share API keys. See Authentication & RBAC.

Tier requirements

FeatureFree (Assess)Monitor+
Dashboard sign-in✓✓
Self-serve first workspace✓✓
Team invites✗✓
SSO Admin PortalEnterpriseEnterprise

Invite linking (technical)

Invites flow through POST /tenant/invites → WorkOS organization invitation → pending TenantInvite row. On first login after accept, membership is created via:

  1. WorkOS webhook organization_membership.created
  2. Pending invite matched by email on dashboard bootstrap
  3. WorkOS webhook invitation.accepted

Ensure the API receives WorkOS webhooks at POST /public/workos/webhook with WORKOS_WEBHOOK_SECRET configured.

Troubleshooting

  • No workspace linked — invitee email must match the invite; re-send invite and verify webhooks.
  • Send invite fails / 402 — tenant is on free tier; upgrade to Monitor.
  • Wrong role after invite — admin updates the role dropdown in Team panel.
  • Removed user still has access — they must sign out; membership delete revokes server-side session keys.

API reference

Authentication & RBAC · Dashboard SSO · Billing & onboarding · Dashboard