Team and roles

Invite people, what each role can do, and how account activity is recorded.

Guides · 1 min read

Roles

  • Owner — full access, including subscription and organisation settings.
  • Admin — full compliance work, including approving policies and managing members.
  • Member — day-to-day work: upload evidence, work tasks, draft policies.

Only owners and admins can approve a policy. That restriction exists so approval carries authority rather than being a button anyone can press.

Inviting people

Invite by email from Settings. Invitations can be revoked before they're accepted. Removing a member deactivates their access immediately.

Account activity

Security-relevant actions are recorded to an append-only audit trail — invitations, role changes, password changes, policy approvals and revisions, risk changes, framework activation, and connecting or disconnecting an integration. Each entry records who acted, when, and from which address.

More in Guides

Policies and approvalAdopt from templates or write your own, take a policy through review, and keep a versioned approval record.Access reviews and offboardingFind access that should have been removed, and confirm independently that it actually was.Reports and the audit binderReadiness reports, the SOC 2 system description, and a one-click export of everything an auditor asks for.
← All documentation