Users & Roles
CBOM uses JWT-based authentication with two roles: Admin and Viewer.
First-Time Setup
Section titled “First-Time Setup”On first deployment, no users exist. Create the initial admin account:
- Navigate to the platform URL — you’ll be prompted to create an admin account
- Or use the API:
POST /api/v1/auth/register-admin
This endpoint only works once. After the first admin is created, all subsequent users must be created from the admin panel.
| Role | Permissions |
|---|---|
| Admin | Full access — create/edit/delete sensors, scanners, users, settings, trigger scans, import data, manage compliance standards |
| Viewer | Read-only access — browse inventory, view dashboard, view compliance results, export data |
Managing Users
Section titled “Managing Users”Navigate to Users in the sidebar (admin only).
Create a User
Section titled “Create a User”- Click Create User
- Enter username, password (minimum 4 characters), display name
- Select role: Admin or Viewer
- Click Create
Change Role
Section titled “Change Role”Click the role badge on any user to toggle between Admin and Viewer.
Delete a User
Section titled “Delete a User”Click Delete on the user row. You cannot delete your own account.
Authentication
Section titled “Authentication”Users authenticate with username and password. The API returns a JWT token valid for 24 hours.
Token Refresh
Section titled “Token Refresh”Tokens expire after 24 hours. The UI handles re-authentication automatically when a token expires.
Session Security
Section titled “Session Security”- Tokens are signed with the
CBOM_JWT_SECRETenvironment variable - Tokens contain the username and role — no database lookup on each request
- Sign out invalidates the token on the client side
Sensor Authentication
Section titled “Sensor Authentication”Sensors use a separate authentication mechanism — API keys issued during registration. Sensor API keys do not expire and are not tied to user accounts.
Related
Section titled “Related”- Settings — Platform configuration
- Licensing — License limits on user count
- Deployment — Initial setup