Quick start for workspace admins
Create a Vulnara workspace, invite your team and set roles, add git tokens, create a CI service account, set alert rules and check plan usage.
This guide sets up a workspace for a team: people with the right roles, credentials for private code and CI, alerts, and a view of your plan. You do all of it in the web app at vulnara.rso.dev, and most of it needs the ADMIN role.
Create a workspace
Open the account menu, choose Create New, give the team a Name and submit. Vulnara creates the workspace, makes you its ADMIN and switches you into it.
The name must not already be taken. It is also the workspace id that the CLI and the GitHub Action ask for.
Invite members
Open Settings, then Team, and choose Invite Team Member. Enter the person's Email and choose Invite.
- Someone who already has a Vulnara account gets an email with a link to accept the invitation in the app.
- Someone without an account gets a link that lets them create one and join in the same step.
Pending invitations are listed on the same screen. Choose Revoke to cancel one.
Set roles
Everyone who joins starts as VIEWER. To change a role, select one member in the team list and choose Update Team Member Roles. The roles are:
- VIEWER: reads everything in the workspace, and can download reports.
- EDITOR: also adds repositories and git workspaces, starts and schedules scans, triages findings and manages alert rules.
- ADMIN: also manages members, git tokens, service accounts and the plan.
A higher role includes everything below it. Members who lack a role still see the buttons for it, disabled and naming the role they need. See Teams and roles.
Connect git tokens
Git tokens let Vulnara clone private repositories and, if you allow it, open issues and fix pull requests. Open Access & Security, then Git Tokens, and choose Add Git Token.
- Workspace: the git workspace (GitHub or GitLab organisation or user) the token is for.
- Name: for your reference.
- Value: the token. For GitHub, use a classic token with the
reposcope, or a fine-grained token with read and write access to Contents, Issues and Pull requests. For GitLab, use a token with theapiscope. - Expires At: optional. Leave it blank to use the token's own expiry.
Vulnara checks the token with the provider before saving it. See Connect GitHub or GitLab.
Create a service account for CI
Open Access & Security, then Service Accounts, and choose Create Service Account. Give it a Name and an Expires At date.
Vulnara shows the secret once. Tick the box to confirm you have stored it, then close the dialog. Give the account's name, shown in the list, and the secret to whoever sets up CI. See Service accounts and GitHub Action.
Set alert rules
Open Settings, then Alert Rules, and choose Create Alert Rule. Pick a Channel Type (Email, Webhook, Slack, Discord or Telegram), the recipients, and the Scopes: the events that should trigger it, such as Scan Failed. Choose Create, then Send test. See Alerts.
Check your plan and usage
Open Settings, then Billing. Plans shows the available plans and the one you are on. Usage this month shows git and network scan minutes, repositories, networks and alert emails against your plan's allowance. A warning appears as you get close to a limit. See Plans and billing.
Good to know
- Removing a member takes them out of this workspace only. Their account and their other workspaces are untouched.
- Service accounts are not members. They do not appear in the team list, only under Service Accounts.
- A service account that expires within 7 days, or has already expired, is flagged in the list. Create a new one before the old one runs out, and update your CI secret.
- Deactivate a service account to stop it working without deleting it. Deleting cannot be undone.