Users & Roles
Invite your team and control exactly what each person can see and do.
Inviting people
You add users by email. Each invitation carries a role and a department, and the new user sets their own password from the invite link — you never handle their credentials.
Send an invite
Enter the person's email, choose their role and department, and send. They receive a secure invite link.
They set a password
The user opens the link, sets their own password, and configures two-factor authentication if it is enforced.
Manage over time
Resend or revoke pending invitations, deactivate users who leave, or reset a user's two-factor authentication if they lose their device.
How access is controlled
Access depends on role AND department. Most users see only their own department's records. The Risk & Compliance role sees everything across the organisation, so reserve it for the people who genuinely need an org-wide view.
Roles
| Role | What they can do |
|---|---|
| Administrator | Full access, including settings, users and billing. |
| Risk & Compliance | All registers, approves escalations, manages departments. |
| SLT / MD | Reads the org register and their own department; signs off reviews. |
| Risk Champion | Creates and manages risks within their department. |
| Auditor | Read-only across all modules. |
| Viewer | Read-only within their own department. |
Segregation of duties (SoD)
The role model is designed so the same person can't approve their own work or wave through high-risk changes. Approval flows always separate the requester from the approver:
- Risk escalations — a risk owner requests roll-up to the organisation register; only Risk & Compliance can approve it.
- Independent review — the Auditor role is read-only everywhere, so audit work stays independent of the records being audited.
- Scoped administration — department scoping and per-entity roles keep changes reviewable by someone other than the person who made them, including in multi-entity groups.
Groups
You can also organise people into groups to reflect teams or committees. Groups make it easier to keep related users together and manage them consistently.
Next steps: configure organisation-wide options in Organisation Settings, tighten sign-in with Security & 2FA, and periodically confirm access is correct with Access Reviews.