Authentication and access control

How users sign in to SBOM Observer, how sessions are managed, and how roles limit what a member can do.

Users sign in to SBOM Observer with an identity provider, a passkey, or a one-time code sent by email. There are no passwords. What a user can do once signed in depends on their role in the organization.

Sign-in methods

  • Identity provider: Google, Microsoft, or GitHub.
  • Passkey: a WebAuthn credential on a device or hardware key.
  • One-time code: enter the account email and SBOM Observer sends a code to it. This works without a linked provider or passkey, so a provider outage doesn't lock a user out.

Users can't sign up on their own; they join an organization by invitation.

Security settings

The user menu in the lower-left corner opens Account Settings. Its Security Settings tab is where a user:

  • links or unlinks identity providers,
  • adds and removes passkeys,
  • reviews active sessions and revokes any of them.

Roles

Signing in establishes who the user is. Their role in the organization decides what they can do: owner, admin, member, or viewer, with billing as an add-on role. Members can read and write namespace data, viewers can only read it, and admins and owners also manage namespaces and the organization. See Roles and permissions for the full matrix.

Access tokens for the CLI and API are a separate mechanism, created per user from the user menu. See Access tokens.