Collaborator Management
Manage external collaborator access and permissions.
Collaborator Management
The Collaborators page in the Admin section lets you manage external collaborators — people outside your organisation who need temporary access to specific playbook sections. This page provides tools for inviting collaborators, assigning section-level access, enforcing MFA, monitoring activity, and revoking access.
Inviting External Collaborators
To invite an external collaborator:
- Navigate to Admin → Collaborators
- Click Invite Collaborator
- Enter the collaborator's name and email address
- Select one or more playbook sections to grant access to
- Optionally set an access expiry date
- Click Send Invitation
The collaborator receives an email with a magic link. On first access, they must set up TOTP multi-factor authentication before they can view any content. See External Collaborators for details on the collaborator experience.
Assigning Sections
External collaborators have section-level access, meaning they can only view and edit the specific sections you assign to them. To manage section assignments:
- Find the collaborator in the list
- Click Manage Sections
- Use the section picker to add or remove section assignments across any of your organisation's playbooks
- Click Save
Changes to section assignments take effect immediately. The collaborator sees the updated access the next time they load the platform.
Principle of Least Privilege
Only assign the sections each collaborator genuinely needs to access. This reduces the risk of unintended exposure of sensitive incident response procedures and ensures compliance with data minimisation principles.
MFA Enforcement
TOTP multi-factor authentication is mandatory for all external collaborators. This cannot be disabled or bypassed. The Collaborators page shows the MFA status for each collaborator:
- MFA Configured— The collaborator has successfully set up their authenticator app
- MFA Pending— The collaborator has received their invitation but has not yet completed MFA setup
If a collaborator loses access to their authenticator app, an administrator can reset their MFA from this page. This invalidates the existing TOTP secret and requires the collaborator to set up MFA again on their next login.
Revoking Access
To revoke a collaborator's access:
- Find the collaborator in the list
- Click Revoke Access
- Confirm the revocation
Revocation is immediate. The collaborator can no longer access any sections, and their magic link and TOTP credentials are invalidated. All activity they performed while they had access remains in the audit log.
Viewing Collaborator Activity
Each collaborator entry on the management page includes an activity summary showing:
- Last login date and time
- Number of sections viewed
- Number of edits made
- Total time spent on the platform
For a full activity history, click View Activity to see a filtered view of the audit log showing only actions by that collaborator. This is useful for reviewing what a collaborator accessed and modified during their engagement.
Information
Collaborator activity is part of the immutable audit log and cannot be deleted or modified, even after the collaborator's access has been revoked.
Was this page helpful?