User Roles¶
SBOM360 recognizes three types of users. What a person can see and do on the platform depends entirely on which type of user they are. Each user type has its own portal, reachable at its own web address, with its own sidebar navigation.
Organization¶
An Organization user manages the platform on behalf of the company that owns the products being tracked. Organization users can:
- View a Security Dashboard summarizing critical vulnerabilities, pending VEX requests, and recent scan activity.
- Invite, onboard, and manage vendors, including setting SBOM quality requirements for each vendor.
- Create and manage products, and assign products to vendors.
- Add customers and record their product deployments.
- Upload SBOMs directly, or receive them from vendors, and link SBOMs to products.
- Triage vulnerabilities across every linked SBOM — reviewing, assigning, escalating, and applying VEX overrides.
- Send vulnerability notifications to customers and vendors, and track acknowledgment through the alert workflow.
- Respond to customer VEX requests and review vendor-submitted VEX documents.
Vendor / Supplier¶
A Vendor is a company that supplies software components or products to an organization. Vendor users can:
- View a personal dashboard summarizing SBOM submissions, pending alerts, and onboarding progress.
- View the products assigned to them by the organization.
- Upload and version SBOMs for their products, either through the portal or via CI/CD using an API token.
- Receive and respond to vulnerability alerts from the organization.
- Submit VEX statements — proactively or in response to an alert — declaring whether a vulnerability affects their product.
- Manage their company profile and API access token.
Vendors cannot create products themselves; products are created and assigned to them by an organization. Vendors only see their own submissions and the products assigned to them.
Customer¶
A Customer is a user who deploys an organization's products and wants to stay informed about vulnerabilities affecting those deployments. Customer users can:
- Register and manage their own product deployments, including version, environment, and deployment date.
- View a Security Inbox of vulnerability notifications sent by the organization.
- Acknowledge alerts, mark them as under investigation, or confirm a fix has been applied.
- Submit VEX requests asking the organization or vendor whether a specific CVE affects a specific deployment.
- Manage their own profile and notification preferences.
Customers can only see their own deployments and their own notifications; they cannot see other customers' data or any internal organization or vendor screens.
What each user type can see — quick comparison¶
| Capability | Organization | Vendor | Customer |
|---|---|---|---|
| Manage products | Yes, full catalog | View assigned only | No |
| Upload SBOMs | Yes, any product | Yes, assigned products | No |
| Triage vulnerabilities | Yes, all linked SBOMs | No | No |
| Send notifications | Yes, to vendors & customers | No | No |
| Receive notifications | N/A | Yes | Yes |
| Respond with VEX | Yes (override) | Yes | No — can only request |
| Request VEX | N/A | No | Yes |
| Manage vendors / customers | Yes | No | No |
| Register deployments | Yes, on a customer's behalf | No | Yes, own only |
Note
If you try to open a page or perform an action that your user type is not allowed to use, the platform blocks the action and redirects you to your own portal. Menus and buttons for actions you cannot use are simply not shown to you.