Hugging Face access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Hugging Face, Black Cat runs 3 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Hugging Face connector needs.
Checks (3)
severity: high Resource Group Auto-Join With Write Access fix difficulty: medium #
Avoid auto-joining every org member to a resource group at write/admin role
- Open Organization Settings > Resource Groups and select the group
- Disable "Include all org members" (auto-join) or lower the auto-join role to read
- Re-grant write/admin only to members who require it
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Excessive Organization Admins fix difficulty: medium #
Reduce the number of organization administrators
- Open Organization Settings > Members and review admin-role members
- Downgrade non-essential admins to write or contributor
- Keep a minimal set of break-glass admins
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3
severity: low Member With Org Admin Role fix difficulty: easy #
Review members holding the organization admin role
- Open Organization Settings > Members
- Confirm each admin genuinely requires org-wide administrative rights
- Downgrade where possible
Satisfies: NIS2 Directive NIS2-21.i.4 DORA (SaaS Security) DORA-9.3