> For the complete documentation index, see [llms.txt](https://onsecurity.gitbook.io/test-flow/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://onsecurity.gitbook.io/test-flow/administration/user-levels.md).

# User Permission Levels

As mentioned in the `Adding a User` page, there are 3 permission levels that can be assigned to a user:

* Admin
* Editor
* Read Only&#x20;

An overview of what each permission enables a user to do:

![](https://i.imgur.com/OjGzwIh.png)

### Admin Permissions

Assign a user the Admin Permission if you require a user to:

**View & Edit Targets**

Users have the ability to view the target scope of a test, and edit the scope targets if required.

**View Findings & Request Re-tests**

Users are able to view any findings found on a test, and request a re-test of the findings once they have been rectified.

**View & Use Platform Administration**

Users are able to view the platform administration and use the options within to manage billing, view testing history, integrate to JIRA and upload/view files via file management.

**Buy Additional hours**

This permission allows a user to purchase additional testing hours.

**Create API Keys & Use API**

The user has the ability to create API keys which enable the user to perform actions on the portal via the API.

**Manage Users**

This permission enables the user to manage users via the platform administration including the ability to add and disable users.

### Editor Permissions

Assign a user the Editor permission if you require the user to:

**View & Edit Targets**

Users have the ability to view the target scope of a test, and edit the scope targets if required.

**View Findings & Request Re-tests**

Users are able to view any findings found on a test, and request a re-test of the findings once they have been rectified.

**View & Use Platform Administration**

Users are able to view the platform administration and use the options within to manage billing, view testing history, integrate to JIRA and upload/view files via file management.

**Create API Keys & Use API**

The user has the ability to create API keys which enable the user to perform actions on the portal via the API.

### Read Only Permissions

Assign a user the Read Only Permission if you require the user to:

**View Targets**

Users have the ability to view the target scope of a test.

**View Findings**

Users are able to view any findings found on a test.

**View Platform Administration**

Users are able to view the platform administration page including the option to view the testing history and upload files.
