Inviting Users
1
Go to Settings → Users
Click Add User.
2
Enter the user's details and role
Enter the user’s name and email, check Invite to VISO TRUST, and select their role: Admin, Program Manager, Contributor, or Viewer. See Role-Based Access for a breakdown of what each role can do.
3
Send the invitation
The user receives an email with a link to set up their account. If SSO is configured, their first login must go through your SAML identity provider — social logins (Google, Microsoft) work after the first successful SSO login.
Changing a User’s Role
From Settings → Users, select the three-dot menu next to any user and select Edit. Update their role and save. Role changes take effect immediately.Removing a User
Select the three-dot menu next to the user and select Delete. Removing a user:- Revokes their platform access immediately
- Does not delete their past activity, comments, or audit trail entries
- Does not automatically reassign relationships they own as Business Owner — update Business Owner assignments separately
Default Subscribers
A Default Subscriber is automatically subscribed to every relationship in the organization — existing and future. Use this for centralized risk or compliance teams that need visibility across the entire vendor portfolio. To enable:- Select the three-dot menu next to the user → Edit
- Check Default Subscriber
- Click Save
Business Units
Every user belongs to a Business Unit, which is set when they’re created or edited. Business Units determine which unit a relationship is attributed to when the user is assigned as Business Owner. To manage Business Units, go to Settings → Business Units. See Business Units for details.Service Accounts for API Access
If you’re using the VISO TRUST API for automation or integration, use a dedicated service account rather than a personal user account. This ensures API access isn’t tied to an individual’s employment status and makes it easier to manage token lifecycle. To create a service account:- Invite a new user with a service account email (e.g.,
viso-api@yourorg.com) - Assign the Admin or Program Manager role — the API endpoints require program-level access
- Log in as that user to generate an API token from the user profile