Inviting Users
1
Go to Settings → Users
Select Add User.
2
Enter the user's details and role
Enter the user’s name and email, check Invite to VISO TRUST, and select their role: Admin, Program Manager, Contributor, or Viewer. See Role-Based Access for a breakdown of what each role can do.
3
Send the invitation
The user receives an email with a link to set up their account. If SSO is configured, their first login must go through your SAML identity provider — social logins (Google, Microsoft) work after the first successful SSO login.
Changing a User’s Role
From Settings → Users, select the three-dot menu next to any user and select Edit. Update their role and save. Role changes take effect immediately.Removing a User
Select the three-dot menu next to the user and select Delete. If the user has relationship subscriptions, Business Owner assignments, or Assessment Lead assignments, the delete dialog prompts you to reassign them first. Select another user to receive the assignments, then select Reassign and Delete Contact. These counts include archived relationships, so a user may need reassignment even if they own nothing in your active portfolio. Removing a user:- Revokes their platform access immediately
- Does not delete their past activity, comments, or audit trail entries
Default Subscribers
A Default Subscriber is automatically subscribed to every relationship in the organization — existing and future. Use this for centralized risk or compliance teams that need visibility across the entire vendor portfolio. To enable:- Select the three-dot menu next to the user → Edit
- Check Default Subscriber
- Select Save
Business Units
Every user belongs to a Business Unit, which is set when they’re created or edited. Business Units determine which unit a relationship is attributed to when the user is assigned as Business Owner. To manage Business Units, go to Settings → Business Units. See Business Units for details.Service Accounts for API Access
If you’re using the VISO TRUST API for automation or integration, use a dedicated service account rather than a personal user account. This ensures API access isn’t tied to an individual’s employment status and makes it easier to manage token lifecycle. To create a service account:- Invite a new user with a service account email (e.g.,
viso-api@yourorg.com) - Assign the Admin or Program Manager role — the API endpoints require program-level access
- Log in as that user to generate an API token from the user profile