Skip to content

Team Members

Security is a team effort. CVEFeed.io lets you invite colleagues to your project so everyone has visibility into the vulnerabilities affecting your software stack. Each project maintains its own member list with role-based access control, ensuring that the right people have the right level of access.

Members are scoped to individual projects — being a member of one project doesn’t grant access to another. This makes it safe to create separate projects for different teams, clients, or environments without worrying about information leaking across boundaries.

Every project member is assigned one of three roles. Roles determine what actions a member can take within the project:

RoleWhat they can do
OwnerFull control over the project — manage billing, delete the project, promote/demote members, and everything admins can do. Each project has exactly one owner (the person who created it).
AdminManage the project’s day-to-day operations — add or remove product subscriptions, configure alert channels and integrations, invite and remove members, create API tokens, and — on Enterprise projects — read the activity log, both in the app and through the API.
MemberRead access to the project’s vulnerability data and alerts, plus the ability to add and remove product subscriptions from the Tech Stack Management page — so members can change what the project monitors. They can’t invite or remove members, change roles, create API tokens, configure integrations, add email recipients, change project settings, or view the activity log.

Choose roles based on responsibility: give Admin access to team leads who manage members, tokens, and integrations, and Member access to developers or analysts who follow the project’s CVEs and keep its tech stack current. There is no strictly read-only role — every member can edit the monitored product list, and their additions count against the owner’s subscription quota.

From your project, go to the Members page. You’ll see the current member list, their roles, and any pending invitations.

Project members page showing the member list with roles and the invite button

To invite someone:

  1. Click the Invite Member button in the top right.
  2. Enter their email address.
  3. Click Send Invite.

Everyone joins as a Member — the invite form has no role picker. Once the person accepts, the project owner can promote them to admin from the members table.

The invited person will receive an email with a link to join the project. If they don’t have a CVEFeed.io account yet, they’ll be prompted to create one first — the invitation will be waiting for them once they sign up.

The Pending Invitations section at the bottom of the members page shows all outstanding invitations. From here, admins and owners can see which invitations are still waiting to be accepted and can revoke them if needed.

Invitations expire 7 days after they are sent. If someone misses the window, simply send a new invitation.

As your team evolves, you may need to adjust access:

  • Change a role: Owners can promote a member to admin, or demote an admin to member, directly from the members table.
  • Remove a member: Owners and admins can remove members who no longer need access. This takes effect immediately — they’ll lose access to the project’s data.
  • Transfer ownership: Project ownership cannot be transferred through the UI. If the project owner needs to leave, contact support to arrange the transfer.

Each project has a limited number of member slots determined by the project owner’s subscription tier. This count includes active members, pending invitations, and custom email recipients — all share the same pool.

TierMember slots per project
Free1
Starter3
Pro5
Enterprise10

With your team in place, make sure everyone is getting the right notifications: