Decision LighthouseDecision Lighthouse documentation
Open Admin Dashboard
For organization administrators

Organization Admin Guide

Operate Decision Lighthouse for one organization: onboard people, protect tenant boundaries, configure organization settings, and keep decision work reviewable.

Organization admins can manage ordinary users and organization-scoped resources. They cannot manage super admin accounts or other organizations.

Access and responsibilities

Open /admin from the Account section or the Admin Dashboard link. The server checks your role and organization on every protected action.

You can manage

Users in your organization, organization name/domain, PATHScan link, organization statistics, audit logs, scheduled reports, webhooks, vulnerability policy, report history, and organization presentation templates.

You cannot manage

Super admin accounts, users in another organization, platform-wide organization records, or cross-organization data. You cannot promote a regular user to organization admin.

Tenant boundary: stay in your organization context when reviewing reports, assessments, audit entries, tasks, templates, and vulnerability decisions. The API enforces organization scoping; do not copy data between organizations without authorization.

Onboard a user

  1. Open the user management area in the Admin Dashboard and choose Add User or the equivalent create action.
  2. Enter the person’s name and email, then select the lowest role needed for the job. Confirm the organization context before saving.
  3. Review the default access options, including report viewing, assessment creation, export, implementation views, friction points, and Gantt access. Give only what the person needs.
  4. Set a trial expiration when your organization uses trial access. New users default to a 30-day trial if no date is supplied.
  5. Save the user. Decision Lighthouse provisions the identity through Auth0 and may show a pending provisioning state until the identity provider completes.
  6. Send onboarding instructions through your approved channel. Do not send credentials in an unsecured note or place them in Decision Lighthouse content.

Use the user list to check active status, role, provisioning state, and last login where available. If a user cannot sign in, check provisioning status first, then use the supported reset-password action.

Role boundaries

RoleTypical useImportant boundary
UserCreate assessments and work with own decision content.Does not access the admin dashboard or organization-wide history.
AnalystReview assessment and report history and support decision analysis.Vulnerability prioritization is restricted from analyst and auditor roles in the current policy.
AuditorReview reports and history for oversight.Should not be used for routine creation or prioritization work.
AdminManage the organization and its users and outputs.Cannot create or manage super admins, assign admin to a lower role, or cross organization boundaries.
Super adminPlatform-wide operations.Use the separate Super Admin Guide; organization admins should not attempt to emulate this role.

Configure organization settings

  1. Confirm the organization name and email domain. Keep the domain aligned with the identity and onboarding process your organization uses.
  2. If your organization uses PATHScan, set the PATHScan URL. The URL must use HTTPS. Verify the link from the main Decision Lighthouse Start screen.
  3. Save changes and test the user-facing link in a separate browser tab.

Do not paste AI keys or other secrets into documentation or general settings. AI connection settings are a separate operational concern; use your organization’s approved secret-management process.

Governance and review

Audit logs

Use audit logs to review administrative actions, report operations, user changes, and other tracked events. Filter by time, action, user, or resource where the dashboard provides those controls. Treat audit data as a governance record and preserve it according to policy.

Reports and history

Organization admins can view organization-scoped report history, open report details, and remove reports when policy allows. Before deleting a report, confirm that stakeholders no longer need it and that an approved retention or export record exists. Report deletion is destructive.

Scheduled reports and webhooks

Configure scheduled reports only for approved recipients and approved cadence. Review webhook destinations, authentication expectations, and data classification before enabling them. Remove stale schedules and endpoints promptly.

Presentation templates

Upload an approved organization presentation template when your deployment enables templates. Verify branding, audience, and the template’s ownership before making it available. Keep templates within the organization’s data boundary.

Vulnerability Management administration

  1. Review the organization’s VM policy before prioritizing a new list. A policy should reflect the organization’s approved approach to severity, exposure, critical services, sensitive data, deadlines, and capacity.
  2. Use governance-document extraction to inform analysis context when appropriate. Confirm that uploaded documents are authorized and contain no secrets.
  3. Enter analysis-only context and SLAs. Ensure Critical, High, Medium, and Low targets match the organization’s policy.
  4. Approve only after reviewing rejected-row notices, ranked findings, key factors, next actions, and root-cause intelligence.
  5. Use approved decision history and outcomes to support remediation governance. Do not assume an approved ranking means a finding is remediated.
Retention behavior: approved vulnerability history retains derived decision snapshots. Uploaded source bytes and descriptions are not retained.

Strategic Plan Prioritization administration

Help users distinguish between the plan’s source material and the derived ranking. The flow extracts initiatives, asks up to 10 bounded-choice questions, and requires a server-calculated context score of 100% before ranking.

  • Ask users to verify extracted initiative names and preserve unknowns rather than guessing.
  • Review Do Now, Do Next, and Do Later labels as decision support, not as an automatic approval.
  • Dependencies are shown by name. Inferred dependencies do not automatically change priority scores.
  • Saving is opt-in and retains only the approved derived ranking, name, rationale, and approval date—not the source plan or pasted text.

Recommended access review

  • Review active users and roles monthly and after organizational changes.
  • Disable users who leave or no longer need Decision Lighthouse.
  • Confirm that report, export, implementation, and admin permissions match the person’s responsibilities.
  • Review audit logs for unexpected user, report, template, webhook, and schedule changes.
  • Check that PATHScan and webhook URLs are still owned and use HTTPS.
  • Remove obsolete reports, schedules, templates, and endpoints only after retention requirements are satisfied.

Important limitations

  • Free-email accounts are intentionally restricted to their own data and cannot create users, create public invitations, or use some password-management actions.
  • Public invitation tools are not a general replacement for normal organization user provisioning; the current public-invite path is limited to the configured Crash Test Humans flow and short-lived invitations.
  • An organization admin cannot delete their own account, manage super admin accounts, or transfer a user to another organization.
  • Every mutating request is protected by the authenticated session and CSRF controls. Do not bypass the UI or share session access.

When to involve a super admin

Escalate when you need to create or delete an organization, transfer users across organizations, manage super admin accounts, change trial dates across tenants, or investigate a cross-organization platform issue. Include the organization, affected user or resource, time of the event, and the relevant audit entry—never include passwords or tokens.