Skip to content
All guides

Repository edition · v1

Manage your team

Every application belongs to an organisation. Knowing an organisation's name, domain or application ID does not grant access.

Roles

Owners manage organisation settings, invite members, issue scoped tokens and approve eligible releases. Editors manage application metadata, findings, incidents and evidence. Viewers can read their organisation's records.

Organisation owners are not BuildVouch platform administrators. CMS access uses a separate operator allowlist.

Invite a colleague

An owner verifies their authenticator, opens Settings and creates an invitation for a work email and role. The app returns a single-use invitation link. Copy it and send it through your approved communication channel; V1 does not send invitation email automatically.

Invitations expire after seven days. The recipient must sign in with the matching verified email and accept personally. Owner invitations additionally require the recipient to verify an authenticator. Revoked, expired, used or wrong-account invitations are rejected.

Invitations do not silently change an existing member's role.

Change a role

An owner with recent MFA may change another member's role in Settings. You cannot change your own role. The final owner cannot be removed or demoted.

Set up an authenticator

Open Security from the workspace navigation. Enrol an authenticator, scan the QR code and confirm a six-digit code. The same screen provides fresh verification before privileged operations.

Pilot ownership

The pre-created Cyclotron organisation can be claimed only by an explicitly allowlisted pilot operator. An empty operator list is a setup task, not a reason to grant the first signup administration.

Mandatory two-factor authentication

Every human BuildVouch workspace session must use a verified authenticator and reach AAL2. This applies to viewers, editors, owners and platform content operators. Invitations can be inspected or accepted only after AAL2. Product-scoped machine tokens do not impersonate a human session; they remain scoped, expiring and revocable.

High-risk actions keep a stricter step-up: release approval, role or invitation changes, API-token changes, Trust Pack export, GitHub connection changes and content publication require a TOTP verification issued within the previous 15 minutes.

Use Account security → Sign out other sessions after losing a device or noticing an unfamiliar session. The current session remains active. Passkeys and printable recovery codes are not represented as available until the authentication provider and recovery procedure are implemented and tested.