Duration: 5 minutes For whom: Admin / Owner of an SME Prerequisite: having a created organisation
CyberPassport manages 4 roles:
| Role | Main permissions |
|---|---|
| Owner | Everything (creator of the org). Only one per organisation. |
| Admin | Everything except deleting the org. Multiple admins possible. |
| Collaborator | Answer questions, upload evidence, view reports. No access to Settings. |
| Auditor | Read-only access to the published assessment and the Evidence Vault. No access to drafts. |
Invite a collaborator
A collaborator is part of your team. They take part in the assessment (answering the questionnaire, uploading evidence).
Steps
- Go to Settings → Team (
/settings/team). - Click "Invite a collaborator".
- Enter their work email address.
- Choose the role: Admin or Collaborator.
- Click "Send invitation".
📸 Screenshot location: collaborator invitation modal
On the invitee's side
The invited person receives an email (subject: "[CyberPassport] {your org} invites you to join their cybersecurity assessment"). By clicking the link:
- If they already have a CyberPassport account (with the same email address): they are added to your organisation immediately.
- If they don't have an account: they go through the signup flow, then are automatically attached.
⚠️ Important: the invitation expires after 72 hours. If the invitee doesn't click within that time, you'll need to re-invite them.
🟣 Tip: to re-invite, on the Team page, find the pending invitation and click "Resend".
Invite an external auditor
An auditor is not a member of your organisation — they are a consultant, a customer, or a regulator to whom you grant read-only access to your published assessment.
Steps
- Go to Settings → Team → Auditors (dedicated section).
- Click "Invite an auditor".
- Enter their email address.
- Click "Send".
📸 Screenshot location: auditor invitation modal
What the auditor sees
- The narrative AI report of your published version only (not your drafts)
- The score by framework and by domain
- The evidence uploaded to the vault, with a download link
- The publication history (the previously sealed versions)
What the auditor CANNOT do
- ❌ Modify your assessment
- ❌ Upload / delete / modify evidence
- ❌ See your drafts in progress
- ❌ Invite other people
⚠️ Important: if you publish a new version after inviting the auditor, they will automatically see the new version the next time their page refreshes — no need to re-invite. The old seal remains verifiable for regulators who may have noted the old hash.
💡 Good to know: the auditor invitation expires after 30 days. Ideal for a one-off audit; for permanent access (e.g. an audit firm tracking your maturity over time), renew the invitation.
Managing my team day to day
See who has access to my org
Settings → Team: lists all members + their role + their join date + their status (active / awaiting invitation).
📸 Screenshot location: Team page with the list of members + auditors
Change a member's role
- On the member's row, click the ⋯ menu → "Change role".
- Choose the new role.
- Confirm.
⚠️ Important: moving an Owner to Admin requires transferring org ownership to someone else first (an Owner must always exist).
Revoke an access
- ⋯ menu → "Revoke access".
- Confirm.
- The person immediately loses access — their JWT token is invalidated at the next refresh.
🟣 Tip: for an auditor, you can also let their invitation expire (30 days) without doing anything. It's less aggressive than a revocation.
Audit log
All sensitive actions (invitation, revocation, role change, publication, evidence deletion) are recorded in Settings → Security → Audit log.
📸 Screenshot location: audit log with a few lines (invite_auditor, publish_assessment, etc.)
Filterable by action type, by user, by date. Exportable to CSV.
Special case — connecting my organisation to a partner (B2B)
If you want to share your report with a customer / supplier / partner who also uses CyberPassport:
- Go to Connected organisations (main sidebar).
- Click "Connect an organisation".
- Search the directory or enter an organisation slug.
- Send a connection request.
- Once the request is accepted, your published report becomes visible on the partner's side.
📸 Screenshot location: Connected organisations page
💡 Good to know: this is different from inviting an auditor. A B2B partner sees your report in their own dashboard (on the large-group side: they see their N suppliers; on the SME side: they see their connected customers).
Next step
→ If you are an invited auditor: For external auditors → If you want to know all about sealing: Verify a sealed report