Skip to main content

Collaborator Management

Manage external collaborator access and permissions.

Collaborator Management

The Collaborators page in the Admin section lets you manage external collaborators — people outside your organisation who need temporary access to specific playbook sections. This page provides tools for inviting collaborators, assigning section-level access, enforcing MFA, monitoring activity, and revoking access.

Inviting External Collaborators

To invite an external collaborator:

  1. Navigate to Admin → Collaborators
  2. Click Invite Collaborator
  3. Enter the collaborator's name and email address
  4. Select one or more playbook sections to grant access to
  5. Optionally set an access expiry date
  6. Click Send Invitation

The collaborator receives an email with a magic link. On first access, they must set up TOTP multi-factor authentication before they can view any content. See External Collaborators for details on the collaborator experience.

Assigning Sections

External collaborators have section-level access, meaning they can only view and edit the specific sections you assign to them. To manage section assignments:

  1. Find the collaborator in the list
  2. Click Manage Sections
  3. Use the section picker to add or remove section assignments across any of your organisation's playbooks
  4. Click Save

Changes to section assignments take effect immediately. The collaborator sees the updated access the next time they load the platform.

Principle of Least Privilege

Only assign the sections each collaborator genuinely needs to access. This reduces the risk of unintended exposure of sensitive incident response procedures and ensures compliance with data minimisation principles.

MFA Enforcement

TOTP multi-factor authentication is mandatory for all external collaborators. This cannot be disabled or bypassed. The Collaborators page shows the MFA status for each collaborator:

  • MFA Configured— The collaborator has successfully set up their authenticator app
  • MFA Pending— The collaborator has received their invitation but has not yet completed MFA setup

If a collaborator loses access to their authenticator app, an administrator can reset their MFA from this page. This invalidates the existing TOTP secret and requires the collaborator to set up MFA again on their next login.

Revoking Access

To revoke a collaborator's access:

  1. Find the collaborator in the list
  2. Click Revoke Access
  3. Confirm the revocation

Revocation is immediate. The collaborator can no longer access any sections, and their magic link and TOTP credentials are invalidated. All activity they performed while they had access remains in the audit log.

Viewing Collaborator Activity

Each collaborator entry on the management page includes an activity summary showing:

  • Last login date and time
  • Number of sections viewed
  • Number of edits made
  • Total time spent on the platform

For a full activity history, click View Activity to see a filtered view of the audit log showing only actions by that collaborator. This is useful for reviewing what a collaborator accessed and modified during their engagement.

Information

Collaborator activity is part of the immutable audit log and cannot be deleted or modified, even after the collaborator's access has been revoked.

Was this page helpful?