Roles
Roles group people by business function so ownership, approvals and reviews can be assigned to a function instead of a single person.
Overview
Roles represent business functions and can be assigned to multiple members. Unlike the organization roles on the People page (Owner, Admin, Member and the others), these roles do not grant permissions. They are used to group members and attach responsibilities to objects such as Assets, Risks, or Policies. A role's members are picked in the role's edit dialog, or from a person's Assign Role action in the People list.
Examples
- CEO: Single user linked to executive responsibilities.
- Developers: Group of technical staff involved with risk and asset management.
- Managers: Leadership group, which may include the CEO and other department leads.
- Team: A collective group where all users are included.
We recommend creating roles per department or function (e.g., Sales, Marketing, Legal) to reflect your organizational structure.
The roles table
Every role is one row. Filter the table by name, sort it by name with the column header, and switch on Show archived to see the roles that have been archived instead of the active ones. The … menu at the end of a row offers Edit, Archive (or Restore for an archived role) and Delete. Archiving states first how many people lose how many assignments.
| Column | Meaning |
|---|---|
Name | The role's name and description. Roles you belong to are marked your role, so you can see where your own responsibilities come from without opening each entry. |
Responsible for | What the role currently carries: the vendors, risks, assets and evidence it owns, the policies and evidence awaiting its approval, the reviews and vendor assessments it runs, and the rest. Three entries are shown; +N more expands the list. |
People | The members of the role. |
Each count in Responsible for matches what the corresponding register shows: archived entries are left out wherever a register has archiving, vendor assessments have no archived state at all, and a review that is already finished still counts towards the role that ran it.
An archived role keeps its entries under Still linked to, because archiving a role does not detach it from the entries that name it, but it no longer makes its members responsible for anything: it is dropped from assignment audiences and is never marked as one of your roles.
Deleting Roles
Deleting a role removes its associations across all linked objects. Carefully review dependencies before deletion.
How is this guide?