Developer portal
Dashboard team, invites, and roles
Tenant admins manage people under Settings → Team members. Roles apply to WorkOS dashboard sign-in, not automation API keys.
Last updated: 2026-06-14
Roles at a glance
| Role | Typical use | Dashboard access |
|---|---|---|
| admin | Workspace owner, IT or security lead | Full settings, team, API keys, SSO, all tabs and exports |
| operator | Engineers running scans and remediation | Scans, monitor, remediate; no team or key admin |
| viewer | Executives, auditors, read-only stakeholders | Overview and scans; compliance widgets; PDF exports only |
Backend APIs enforce the same boundaries. The UI hides tabs and widgets using tenant role policies (see below).
Who can manage the team
Only users with the admin role see the full Team members panel under Settings. Operators and viewers see a notice that admin role is required. Your role appears in the workspace header and in GET /api/dashboard/me → session.role and capabilities.
Inviting a teammate
- Sign in at qtangl.com/dashboard as an
admin. - Open the Settings tab.
- Scroll to Team members.
- Enter the colleague's work email and choose a role (default: operator).
- Click Send invite — WorkOS emails a sign-in link.
After the invitee signs in, Qtangl links them to your tenant with the role you selected. Admins can change roles with the dropdown next to each member, or use Remove to revoke access. Pending invites can be cancelled with Revoke.
Capabilities by role
Computed server-side on login via GET /api/dashboard/me:
canAdmin— settings, team, SSO, audit (admin only)canWrite— run scans, remediation (admin + operator)canViewCompliance— all three rolescanManageKeys— automation API keys (admin only)canInvite— send team invites (admin only, Monitor tier+)
Dashboard visibility (role policies)
Tenant settings include rolePolicies that filter tabs, widgets, and export formats in the UI. Defaults:
viewer— Overview and Scans tabs; PDF exportsoperator— Overview, Scans, Monitor, Remediate; PDF, board, bundle exportsadmin— all tabs and export formats
Admins can override defaults via PATCH /tenant/settings with a rolePolicies object. There is no Settings form for this yet — contact Qtangl support or use the API for customizations. The persona toggle (Operator vs Executive in the header) adjusts layout emphasis only; it does not change security boundaries.
Automation API keys (not human login)
Under Settings → Automation API keys (admin only), create keys for CI, Terraform, and scripts. Each key has its own role. Secrets are shown once at creation. Humans should sign in with WorkOS, not share API keys. See Authentication & RBAC.
Tier requirements
| Feature | Free (Assess) | Monitor+ |
|---|---|---|
| Dashboard sign-in | ✓ | ✓ |
| Self-serve first workspace | ✓ | ✓ |
| Team invites | ✗ | ✓ |
| SSO Admin Portal | Enterprise | Enterprise |
Invite linking (technical)
Invites flow through POST /tenant/invites → WorkOS organization invitation → pending TenantInvite row. On first login after accept, membership is created via:
- WorkOS webhook
organization_membership.created - Pending invite matched by email on dashboard bootstrap
- WorkOS webhook
invitation.accepted
Ensure the API receives WorkOS webhooks at POST /public/workos/webhook with WORKOS_WEBHOOK_SECRET configured.
Troubleshooting
- No workspace linked — invitee email must match the invite; re-send invite and verify webhooks.
- Send invite fails / 402 — tenant is on free tier; upgrade to Monitor.
- Wrong role after invite — admin updates the role dropdown in Team panel.
- Removed user still has access — they must sign out; membership delete revokes server-side session keys.
API reference
Related
Authentication & RBAC · Dashboard SSO · Billing & onboarding · Dashboard
Found an issue? Report documentation feedback