This guide lists the permission scopes that control access to each part of Vendor Pulse, so administrators can grant users exactly the access they need.
This page covers Vendor Pulse only. For the complete cross-product reference — every product's scopes, resource-level roles, groups, and common scenarios — see the Zeron Platform: Complete Permissions & RBAC Reference.
vendor:view). If a user lacks the scope a page needs, they see an "Unauthorized" screen.Manage user accounts and groups under Admin > Management (requires the zitadel:iam permission).
| To do this | Required scope |
|---|---|
| View the vendor risk dashboard | dashboard:view |
| View vendor list and all vendor detail tabs | vendor:view |
| Add vendors (single & bulk), edit vendor profiles | vendor:add |
| Delete vendors | vendor:delete |
| View assessments, responses, history | vendor:assessment:view |
| Create assessments, send reminders, configure scheduling | vendor:assessment:add |
| Review and evaluate vendor responses | vendor:assessment:review |
| Delete assessments | vendor:assessment:delete |
| View vendor risks | vendor:risk:view |
| Create risks, manage lifecycle, send risks to vendors | vendor:risk:add |
| View Digital Risk (DRM) / external attack surface | vendor:digital:view |
| View MasterVault templates, categories, questions | master:view |
| Create/edit templates, categories, questions, import/export | master:add |
| Delete from MasterVault | master:delete |
| View ZIN documents & knowledge base | zin:view |
| Upload documents, manage KB entries, import KB | zin:add |
| Delete ZIN documents | zin:delete |
| View questionnaire checklist & scan results | questionnaire:view |
| Upload questionnaires for AI scanning | questionnaire:add |
| View & download reports | report:view |
Vendors who respond through the Vendor Assessment Portal use roles, not scopes:
| Role | What they can do |
|---|---|
| Admin | Full access: manage team, submit assessments, answer questions, upload documents |
| Collaborator | Answer questions, upload documents, add comments |
| Viewer | Read-only: view questions and responses |
dashboard:view + vendor:view + vendor:assessment:view + vendor:risk:view + master:view + zin:view + questionnaire:viewvendor:*, master:*, zin:*, questionnaire:* + report:view| Issue | What to do |
|---|---|
| User sees "Unauthorized" on a page | Their group/role is missing that page's scope. Add the scope from the table above. |
| User can view but not create/edit | View and add/edit are separate scopes. Add the matching :add scope. |
| User cannot see Reports | Add report:view. |
| Vendor cannot submit in the portal | The vendor needs the Admin or Collaborator role, not Viewer. |
Need more help? Contact support@zeron.one.