incident.io access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On incident.io, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the incident.io connector needs.
Checks (5)
severity: high Excessive Admins fix difficulty: easy #
Reduce the number of Incident.io organisation admins to three or fewer
- Sign in to Incident.io and navigate to Settings > Members
- Review the list of users with the Admin role
- For each admin beyond the required minimum, click the user's role dropdown
- Change their role to a least-privilege role such as Responder or Viewer
- Confirm the role change and repeat for all excess admins
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Single Account Owner fix difficulty: easy #
Designate at least one additional Incident.io account owner to avoid single points of failure
- Sign in to Incident.io and navigate to Settings > Members
- Identify the current sole owner of the organisation
- Select a trusted admin-level user and open their role settings
- Promote them to the Owner role
- Confirm the change and verify at least two owners are now listed
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium User Without Base Role fix difficulty: easy #
Assign a base role to every Incident.io user that currently has none
- Sign in to Incident.io and navigate to Settings > Members
- Filter or sort by role to locate users with no base role assigned
- Click the affected user's role dropdown
- Assign an appropriate base role such as Viewer or Responder
- Confirm the change and repeat for all users without a base role
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium User Has Custom Roles But No Base Role fix difficulty: easy #
Assign a base role to users who have custom roles but lack a base role to avoid ambiguous permission sets
- Sign in to Incident.io and navigate to Settings > Members
- Locate the user flagged by this policy
- Click the user's role settings and review their current custom role assignments
- Assign an appropriate base role (e.g., Viewer or Responder) that matches the intended access level
- Confirm the change and verify the user's effective permissions are now unambiguous
- Repeat for all affected users
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.2 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low User With Excessive Custom Roles fix difficulty: easy #
Review and reduce custom role assignments for users who hold three or more custom roles to limit privilege creep
- Sign in to Incident.io and navigate to Settings > Members
- Open the profile of the user flagged by this policy
- Review each custom role assigned to determine whether it is still required
- Remove any custom roles that are redundant, expired, or no longer needed
- Confirm the user retains only the minimum roles necessary for their responsibilities
- Schedule periodic access reviews to prevent role accumulation over time
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2