Skip to main content

Users and roles

Settings → Users

The roles

Roles are hierarchical — each one can do everything below it.

RoleCan
Super adminEverything, across organisations.
Org adminManage users, settings and configuration for this organisation.
ManagerCreate and run engagements; approve and sign off work.
AnalystDo the work — assess controls, score risks, upload evidence.
ViewerRead only. Cannot change anything, anywhere.

Inviting someone

  1. Settings → Users → Invite user
  2. Enter their email, name and role.
  3. They receive an email with a link to set their own password.

You never set another person's password. If someone cannot sign in, send a password reset rather than creating a second account for them — duplicate accounts break the segregation-of-duties checks described below.

Segregation of duties

Several actions deliberately cannot be done by one person alone. This is not a permissions bug; it is the control working.

  • A control workpaper prepared by you must be reviewed by someone else.
  • An audit milestone you completed must be approved by someone else.
  • A remediation action you own must be verified by someone else.

If you find yourself blocked with a message about segregation of duties, the answer is to involve a second person — not to change your own role.

A one-person team cannot complete these workflows

If your organisation has a single user, sign-off chains cannot be finished. Add at least a second named user before running a real engagement.

Engagement teams

Being an org member is not the same as being on an engagement. Assessment and audit engagements have their own team lists with roles like preparer, reviewer and approver, assigned per engagement. Someone must be on the engagement team in the right role before they can sign anything off.