Role-based Access Control

The Censys Platform uses role-based access control (RBAC) to provide granular access control for users and resources. This document explains the various roles, their permissions, and how relationships to resources enhance functionality and security.

User roles

The following roles are available in the Censys Platform.

Platform-wide roles

RolePermissions
Platform AdminBilling, user and role management, audit log, AI privacy configuration, authentication settings, and account management APIs. Does not consume a module seat.
API AccessGrants Platform API endpoint access scoped to the user’s module and role combination. API Access is an additional permission added to a user's account and it does not consume a seat. Users with this role can generate, edit, and delete Personal Access Tokens.

Module roles

RolePermissions
Global Search - AnalystBase Platform access and the default role for new members. Grants access to search, collections, history, and other Platform features. Includes access to the Adversary Investigation and Critical Infrastructure modules, if they are available to the organization.
Global Search - ManagerEverything in the Global Search - Analyst role plus collection (including collection webhooks) and tag management for the organization.
ASM - AnalystBase access to ASM workspaces. Does not have access to ASM workspace API keys. Does not consume a Global Search seat.
ASM - ManagerEverything in the ASM - Analyst role plus the ability to administer ASM workspaces. Does not consume a Global Search seat.

Default roles for SAML SSO users

Organizations with SAML SSO configured auto-provision users on their first login. The Platform sets the default role based on the products an organization has access to, as described in the table below.

ProductsDefault role
Platform (including Adversary Investigation and Critical Infrastructure modules)Global Search - Analyst
Platform and ASMGlobal Search - Analyst (ASM - Analyst must be added separately)
ASM onlyASM - Analyst

Legacy user roles before September 2026

Prior to a September 2026 update, the Platform used the following roles. The second column explains which role or roles the legacy roles map to after the update. Legacy user roles did not lose permissions as a result of the migration.

Users with the API Access role prior to the September 2026 update retained the role after the update.

Legacy roleNew role(s)
Admin in a Platform organizationPlatform Admin
Global Search - Manager
Admin in an ASM organization that also has a Platform licensePlatform Admin
Global Search - Manager
ASM - Manager
Admin in an ASM organization that does not have a Platform licensePlatform Admin
ASM - Manager
Member in a Platform organizationGlobal Search - Analyst
Member in an ASM organization that also has a Platform licenseGlobal Search - Analyst
ASM - Analyst
Member in an ASM organxization that does not have a Platform licenseASM - Analyst
Member or admin with the API Access roleAPI Access plus any additional roles as shown above

Assign and edit roles

Follow the steps below to edit a user's role. This operation can be performed after a user accepts their invite.

📘

Note

You must be a Platform Admin to grant, edit, or revoke roles.

  1. In the Censys Platform web console, hover your cursor over the organization icon in the left-side navigation panel and select Settings.

  2. Select Members.

  3. Click the three-dot menu to the right of the member.

  4. Click the edit icon.

  5. Apply the appropriate roles and click Update.

Manage roles via API

You can also use the account management API to manage user roles.

Seat limits

When you exceed your seat limit, you will see a warning on the Members page.

Service accounts do not consumer a user seat.




Did this page help you?