Overview
This article explains the permission levels required to view and manage different elements of the mitigation graph in Hyver. Whether you're building routes, creating findings, or linking remediation assets, your ability to take action depends on your assigned role and permissions.
Who Can Edit the Mitigation Graph?
To edit the mitigation graph, you must be:
An Administrator or Power User
With Findings and Graph Initiator permission
This level of access allows you to modify the structure of the graph at the company level.
Permissions for Editors
If you're working at the engagement level, you need the Editor role plus the Findings and Graph Initiator permission to:
Create findings
View findings in the Your Findings tab of the creation wizard
Create or delete edges in the graph
Link remediation assets to edges
Without these permissions, you’ll only be able to view — not contribute to — the mitigation graph.
Deleting and Viewing Rules
Users must have view permissions for findings in order to see them on the graph.
Edges created by Hyver cannot be deleted by users.
Edges created by customers cannot be deleted by CYE.
Users can delete positions, including threats or business assets — but only if they are not connected to an edge.
Threats or business assets created by CYE cannot be deleted by users.
Threats or business assets created by the customer cannot be deleted by CYE.
Wrap-up / Next Steps
Knowing who can do what in the mitigation graph helps maintain integrity while still allowing flexibility for collaborative work. Make sure you have the right role and permissions before editing or building routes.
Next, you can explore how to create a graph or start linking findings and assets.
