Skip to content

Hugging Face access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Hugging Face, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Hugging Face connector needs.

Checks (3)

severity: high Resource Group Auto-Join With Write Access fix difficulty: medium #

Avoid auto-joining every org member to a resource group at write/admin role

  1. Open Organization Settings > Resource Groups and select the group
  2. Disable "Include all org members" (auto-join) or lower the auto-join role to read
  3. Re-grant write/admin only to members who require it

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Excessive Organization Admins fix difficulty: medium #

Reduce the number of organization administrators

  1. Open Organization Settings > Members and review admin-role members
  2. Downgrade non-essential admins to write or contributor
  3. Keep a minimal set of break-glass admins

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

severity: low Member With Org Admin Role fix difficulty: easy #

Review members holding the organization admin role

  1. Open Organization Settings > Members
  2. Confirm each admin genuinely requires org-wide administrative rights
  3. Downgrade where possible

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3

More Hugging Face checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial