Skip to content

incident.io access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On incident.io, Black Cat runs 5 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the incident.io connector needs.

Checks (5)

severity: high Excessive Admins fix difficulty: easy #

Reduce the number of Incident.io organisation admins to three or fewer

  1. Sign in to Incident.io and navigate to Settings > Members
  2. Review the list of users with the Admin role
  3. For each admin beyond the required minimum, click the user's role dropdown
  4. Change their role to a least-privilege role such as Responder or Viewer
  5. Confirm the role change and repeat for all excess admins

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Single Account Owner fix difficulty: easy #

Designate at least one additional Incident.io account owner to avoid single points of failure

  1. Sign in to Incident.io and navigate to Settings > Members
  2. Identify the current sole owner of the organisation
  3. Select a trusted admin-level user and open their role settings
  4. Promote them to the Owner role
  5. Confirm the change and verify at least two owners are now listed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium User Without Base Role fix difficulty: easy #

Assign a base role to every Incident.io user that currently has none

  1. Sign in to Incident.io and navigate to Settings > Members
  2. Filter or sort by role to locate users with no base role assigned
  3. Click the affected user's role dropdown
  4. Assign an appropriate base role such as Viewer or Responder
  5. Confirm the change and repeat for all users without a base role

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium User Has Custom Roles But No Base Role fix difficulty: easy #

Assign a base role to users who have custom roles but lack a base role to avoid ambiguous permission sets

  1. Sign in to Incident.io and navigate to Settings > Members
  2. Locate the user flagged by this policy
  3. Click the user's role settings and review their current custom role assignments
  4. Assign an appropriate base role (e.g., Viewer or Responder) that matches the intended access level
  5. Confirm the change and verify the user's effective permissions are now unambiguous
  6. Repeat for all affected users

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.2 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low User With Excessive Custom Roles fix difficulty: easy #

Review and reduce custom role assignments for users who hold three or more custom roles to limit privilege creep

  1. Sign in to Incident.io and navigate to Settings > Members
  2. Open the profile of the user flagged by this policy
  3. Review each custom role assigned to determine whether it is still required
  4. Remove any custom roles that are redundant, expired, or no longer needed
  5. Confirm the user retains only the minimum roles necessary for their responsibilities
  6. Schedule periodic access reviews to prevent role accumulation over time

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More incident.io checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial