jump to content

Roles and permissions

Choose the right the platform role for each person in your organization, from owners and admins to viewers, auditors, and employees.

View as Markdown

Every person in a the platform organization has one role. The role decides what they can see and change in the compliance program. Manage people and roles under People in the organization sidebar.

Use the least privilege that still lets someone do their job.

RoleWho it is forWhat they can do
OwnerA small set of trusted leads who must never lose access to the organizationEverything, including organization settings, SSO/SCIM setup, and removing people
AdminCompliance, security, or IT teammates who run the program day to dayManage the compliance program and most people; cannot delete the organization, remove members, change SSO/SCIM setup, or grant Owner
ViewerStakeholders who need visibility without editing the programRead the program; sign and approve documents when asked
AuditorInternal or external auditors reviewing evidenceRead the records needed for audit; no day-to-day program administration
EmployeeStaff who only need to complete assigned workSee assigned employee documents, sign, and approve when asked

The person who creates the organization becomes an Owner. Keep at least two owners so settings and access remain recoverable if one person leaves.

  1. Open People and click Add Person.
  2. Enter their name and email, then choose a role.
  3. Optionally note whether they are an employee, contractor, or service account — this is organizational context only and does not change permissions.
  4. Send the invitation so they can activate their account.

Until they accept the invitation, they cannot use the organization. Resend the invitation from People if needed.

When someone should no longer have access:

  • Deactivate them to block sign-in while keeping the record.
  • Remove them when they should no longer appear in the organization at all.

Only owners can remove people. the platform will not let you deactivate, remove, or demote the last remaining owner.

Keep membership roles in People, or let your identity provider set them. SCIM creates people as Employee; assign the final role in People.

Open the audit log under SettingsAudit Log to see who changed people, roles, and other organization records. Owners and admins can export the log when you need a dated trail for an audit.

Ultima actualizare: