Organization-scoped access in Evo
Evo data access is now limited to the Snyk Organizations a user can read, leveraging existing Organization hierarchy without requiring migration. Tenant Viewer now grants scoped read access, Tenant Member no longer grants Evo access, and Organization names appear alongside repositories to distinguish duplicates across Organizations.
Starting August 18, 2026, a user's Evo data is limited to the Snyk Organizations they can read.
Until now, everyone with access to Evo saw every repository, asset, and issue in the Tenant. Evo now reuses your existing Snyk Organization hierarchy, so there is nothing new to model and no migration to run. Nobody loses access until an administrator changes their role.
What's new:
Tenant Viewer now grants read access to the assets and issues in the Organizations the user belongs to, and to nothing outside them
Tenant Member grants no Evo access, letting administrators withhold Evo without removing Snyk platform access
Full-Tenant access continues for Tenant Admin and for the two roles ending in "with Evo access"
Organization names appear alongside repositories, distinguishing the same repository imported into more than one Organization
Note for administrators:
Existing users keep their access, and Tenant Viewers gain scoped read access for the first time. New users join as Tenant Member, which carries no Evo access, so each one needs a role change. Scoped users are read only, and assets without an Organization stay hidden, which today means all Agent Supply Chain Security and Continuous Offensive Security data.
Documentation: Access and authentication
Source: original entry ↗