Skip to main content
Rethinking Email Security for the AI Era, August 25th
Blog
AI Threats & Deepfakes

New Feature: Role-Based Access Controls (RBAC)

AUGUST 20, 20254 MIN READ
Adaptive TeamAdaptive Team
Chat with a real personno Slack required
New Feature: Role-Based Access Controls (RBAC)

Key takeaways

  • RBAC introduces six defined roles, Account Owner, Team Admin, Training Manager, Content Manager, Phishing Manager, and Report Viewer, each shaping what a user can see and which actions they can take inside the platform.
  • Account Owners have full platform access and can assign all six roles, while Team Admins have full access but cannot assign the Account Owner role.
  • Only Account Owners and Team Admins can manage user roles, adding new admins or changing existing roles through the Admin Access section at admin.adaptivesecurity.com.
  • RBAC replaces a previously all-or-nothing access model, letting organizations give training teams, phishing specialists, and reporting managers only the permissions their function requires.
  • RBAC joins a suite of enterprise-grade features, including API reporting, audit logs, and multi-channel phishing simulations, aimed at scaling security awareness programs without adding risk.

Introducing Role-Based Access Controls (RBAC) in Adaptive Security: asmarter, safer way to expand security awareness training and phishing simulations.

Security awareness programs work best when everyone can play their part – without introducing unnecessary risk. With Role-Based Access Controls (RBAC), organizations can now safely bring more people into admin.adaptivesecurity.com.

Six roles. Endless flexibility.

RBAC lets administrators assign one of six defined roles to every user. Each role shapes what users see and what actions they can take inside the platform.

The roles are:

  • Account Owner — full access to the platform; can assign all roles
  • Team Admin — full access; can assign all roles except Account Owner
  • Training Manager — focused on training campaigns and content
  • Content Manager — create and edit training and phishing content; manage SCORM
  • Phishing Manager — manage phishing content, campaigns, and triage
  • Report Viewer — dashboards and insights, without editing rights

With these roles, companies can expand confidently – knowing every user has the right access, and nothing more.

Why it matters

Before RBAC, access was all or nothing. Too much access meant higher risk. Too little slowed teams down.

RBAC changes that.

Now organizations can:

  • Empower training teams to design content without campaign controls
  • Assign phishing specialists to run simulations and triage events
  • Give managers reporting-only access to track progress across their teams
  • Scale security awareness training without friction

RBAC joins a suite of enterprise-grade features – like API reporting, audit logs, and multi-channel phishing simulations – that make Adaptive Security smarter, safer, and more complete than ever.

How to get started

RBAC is available today.

To add or update user roles:

  1. Sign in to admin.adaptivesecurity.com
  2. Go to Admin Access
  3. Select “Add an Admin” to invite someone new, or use the three-dot menu to “Change Role” for existing users

Only Account Owners and Team Admins can manage user roles.

Need help? Our Customer Success and Product teams are here to guide you. Email support@adaptivesecurity.com for assistance, or explore our Help Site for step-by-step instructions.

Additional resources are available on our Help Site.

Smarter collaboration. Stronger security.

With RBAC, Adaptive Security customers can expand their programs safely, empower the right people, and accelerate their impact.

Adaptive Team

Adaptive Team

As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.

Get started with Adaptive Security

Get started

Human security for the AI era.