What Does the Scan Admin Role Grant?
This article explains what the Scan Admin role can do in Edgescan.
Version Number: v1.0.1
Published Date: 23 Sept 2026
____________________________________________________________________________
Overview
Scan Admin provides elevated access to manage scanning activity and the resources that support it, scan configuration, credentials, and scheduling, without granting broader organization or user administration.
Best suited for users responsible for the day-to-day management and operation of scanning activity.
What Scan Admin Can Do
- Scan configuration: Full control to create, edit, delete, and view scan configs, plus manage authentication, session verification, and token mappings used by scans.
- Assets: Limited control to view assets and edit them, edit their credentials, manage assessments, manage pause schedules and retests, cancel scans, and manage licence auto-renewal. Cannot create or delete assets themselves.
- Pause schedules: Full control to create, edit, delete, and view.
- Shared credentials:Full control to create, edit, delete, and view.
- Browser recordings & EASM investigations: Full control to create, edit, delete, and view both.
- Licences: Limited control to view and edit licence assignments (no upgrade permission).
- Insights: View only.
What Scan Admin Cannot Do
This role has no access to organization settings, user management, role/permission administration, policy documents, or notification opt-ins and, unlike Asset Admin, cannot create new assets.