Workato access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Workato, Black Cat runs 10 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Workato connector needs.
Checks (10)
severity: high Excessive Admins fix difficulty: easy #
Reduce workspace Environment Admin collaborators to five or fewer
- Log in to Workato and navigate to Workspace Admin > Collaborators
- Review the list of collaborators and identify those with Environment Admin role
- For each collaborator that does not need admin access, click their name
- Change the role to a less-privileged role or remove them from the workspace
- Confirm the change and verify the admin count drops to five or fewer
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Inactive Member fix difficulty: easy #
Remove or deactivate collaborators who have been inactive for an extended period
- Log in to Workato and navigate to Workspace Admin > Collaborators
- Sort or filter collaborators by last login date to identify inactive members
- For each collaborator inactive for 90 days or more, click their name
- Click "Remove collaborator" or change their status to inactive
- Confirm the removal and notify the member if appropriate
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Overprivileged Member fix difficulty: easy #
Assign a more restrictive role to collaborators with excessive privileges
- Log in to Workato and navigate to Workspace Admin > Collaborators
- Locate the collaborator flagged as overprivileged
- Click the collaborator's name to open their settings
- Change the environment or project role to one with least-privilege permissions
- Save the change and confirm the updated role is applied
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a4 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: info No Custom Roles fix difficulty: medium #
Create custom environment or project roles to enforce least-privilege access control
- Log in to Workato and navigate to Workspace Admin > Roles
- Click "Create new role" to define a custom environment or project role
- Set granular permissions appropriate for the team or function (e.g., recipe editor, viewer)
- Save the custom role and assign it to the relevant collaborators
- Review existing collaborators and migrate them from default roles to the new custom roles where appropriate
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Empty Collaborator Group fix difficulty: easy #
Remove or populate collaborator groups that have no members
- Log in to Workato and navigate to Workspace Admin > Groups
- Locate the empty group flagged by this policy
- Review whether the group has any role or project assignments attached to it
- If the group is no longer needed, delete it to prevent stale permission artifacts
- If members should be present, add the appropriate collaborators to the group
- Confirm the group either has members or has been removed
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.2 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Large Collaborator Group fix difficulty: medium #
Split or trim over-populated collaborator groups to limit blast radius
- Log in to Workato and navigate to Workspace Admin > Groups
- Open the group with more than 20 members
- Review the full member list and identify members who no longer need membership
- Remove members who do not require the group's permissions
- If the group serves multiple distinct functions, split it into purpose-specific sub-groups
- Confirm the group membership is below the threshold and access is still appropriate
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.2 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: info No Custom Project Roles fix difficulty: medium #
Define custom project-level roles to enforce least-privilege access for project collaborators
- Log in to Workato and navigate to Workspace Admin > Roles
- Click "Create new role" and set the scope to "Project"
- Define granular permissions for the intended function (e.g., recipe viewer, recipe editor)
- Save the role and assign it to the relevant project collaborators
- Review existing project collaborators and migrate them from built-in roles where appropriate
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Inactive Admin Member fix difficulty: easy #
Remove or downgrade admin members who have been inactive for 60 or more days
- Log in to Workato and navigate to Workspace Admin > Collaborators
- Filter collaborators by admin role and sort by last login date
- For each admin inactive for 60 days or more, click their name
- Either remove the collaborator or downgrade their role to a non-admin level
- Confirm the change and verify the collaborator no longer has admin access
- Notify the user of the access change through your standard offboarding or review process
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.2 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium API Platform Client Excessive Keys fix difficulty: medium #
Revoke unused API keys to reduce the number of active credentials
- Log in to Workato and navigate to Platform > API Platform > Clients
- Open the client with an excessive number of API keys
- Review each key and identify keys that are no longer in use by consuming applications
- Revoke unused keys one at a time, confirming no downstream impact after each revocation
- Document the remaining active keys and their intended consumers
- Schedule regular key audits to prevent future accumulation
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Workspace Single Admin fix difficulty: easy #
Assign at least one additional Environment Admin to avoid a single point of failure
- Log in to Workato and navigate to Workspace Admin > Collaborators
- Identify a trusted team member who should serve as a backup admin
- Invite the member or edit their existing role to "Environment Admin"
- Save the change and confirm the workspace now has at least two admins
- Document the admin roster in your operational runbook
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-32.1c HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2