Roles & Access
Compliance OS uses scoped authorization so that access can reflect what a person is actually responsible for.Access is not one-dimensional
A user may need several conditions to be true before a page or action becomes available:- the account is active,
- the account belongs to the correct client,
- the user is authorized for the engagement,
- the user’s role permits the application or action,
- the content has been published for the appropriate audience,
- the user is assigned or otherwise entitled to the specific item when assignment matters.
Common role patterns
Exact role names can vary by application and engagement, but common responsibilities include:Participant
A participant typically contributes information or completes assigned work. This can include interviews, remediation actions, evidence, notes, or treatment collaboration.Executive
An executive typically focuses on governance, risk decisions, program status, and leadership attention items.Client administrator
A client administrator may have broader visibility or coordination responsibilities within the client-facing environment.A role is an authorization concept, not necessarily a job title. Your organization’s internal title does not automatically determine what Compliance OS should permit.
Engagement-scoped access
Compliance OS can assign a role within a specific engagement rather than giving the same role across every engagement for the client. This is useful when a person participates in one assessment but should not automatically gain visibility into another.Ownership and assignment
Some actions are further restricted by assignment. For example, a user may be able to view a published treatment but only the assigned owner may be expected to complete a specific client action.When access changes
Access may change when:- you are added to or removed from an engagement,
- a role changes,
- an application is enabled or disabled,
- an item is assigned or reassigned,
- a publication is superseded or withdrawn,
- an account is deactivated.