Users and roles
Settings → Users
The roles
Roles are hierarchical — each one can do everything below it.
| Role | Can |
|---|---|
| Super admin | Everything, across organisations. |
| Org admin | Manage users, settings and configuration for this organisation. |
| Manager | Create and run engagements; approve and sign off work. |
| Analyst | Do the work — assess controls, score risks, upload evidence. |
| Viewer | Read only. Cannot change anything, anywhere. |
Inviting someone
- Settings → Users → Invite user
- Enter their email, name and role.
- They receive an email with a link to set their own password.
You never set another person's password. If someone cannot sign in, send a password reset rather than creating a second account for them — duplicate accounts break the segregation-of-duties checks described below.
Segregation of duties
Several actions deliberately cannot be done by one person alone. This is not a permissions bug; it is the control working.
- A control workpaper prepared by you must be reviewed by someone else.
- An audit milestone you completed must be approved by someone else.
- A remediation action you own must be verified by someone else.
If you find yourself blocked with a message about segregation of duties, the answer is to involve a second person — not to change your own role.
If your organisation has a single user, sign-off chains cannot be finished. Add at least a second named user before running a real engagement.
Engagement teams
Being an org member is not the same as being on an engagement. Assessment and audit engagements have their own team lists with roles like preparer, reviewer and approver, assigned per engagement. Someone must be on the engagement team in the right role before they can sign anything off.