Help Centre

Roles & Permissions: What Each Role Can Do

PolicySuite uses role-based access control (RBAC) to ensure each user sees only the features and data relevant to their responsibilities. Assigning the right role to each team member is one of the most important setup decisions you'll make — it determines what they can create, view, approve, and distribute.

Role overview

Role Description Key permissions
org_owner Account owner, full access Everything — billing, user management, all policies
org_admin Organisation administrator All policy operations, user management (cannot change billing)
compliance_admin Compliance team lead Create/edit/publish policies, manage distributions, view audit trail
policy_author Policy writer Create and edit policies (cannot publish without reviewer approval)
reviewer Policy approver Review and approve/reject policy drafts submitted for review
auditor External or internal auditor Read-only access to policies, acknowledgement records, audit logs; cannot edit anything
employee End user View and acknowledge policies assigned to them via distribution

Assigning roles

You can assign or change a user's role at any time from the Team settings page:

  1. Go to Settings > Team
  2. Find the user in the list (use the search bar for large teams)
  3. Click the user's name to open their profile
  4. Click Change Role and select the new role from the dropdown
  5. The change takes effect immediately — the user's session is updated on their next page load

When inviting new team members via Settings > Team > Invite Member, you select their role before sending the invitation. They'll be assigned that role as soon as they accept and create their account.

Role limits and uniqueness

There is no cap on how many users can hold most roles — you can have as many policy_authors, reviewers, or employees as your subscription allows. The one exception is org_owner: only one user per organisation can hold this role at any time.

To transfer org_owner to a different user:

  1. Go to Settings > Team
  2. Click the target user
  3. Select Transfer Ownership
  4. Confirm the transfer — you'll be downgraded to org_admin automatically

Permission inheritance

Roles are ordered by permission scope. Higher roles inherit all permissions of the roles below them in the hierarchy:

The auditor role in practice

The auditor role is designed for external auditors conducting ISO 27001, SOC 2, or similar assessments. You can invite an auditor with a temporary email address and they'll have read access to:

Auditors cannot modify, delete, or export data. When their engagement ends, remove their account from Settings > Team.

Best practice: Assign the employee role to all staff by default. Only grant elevated roles (policy_author, compliance_admin) to team members who actively manage policies. Over-provisioning roles is a common audit finding — principle of least privilege applies to your compliance platform just as much as to your production systems.

Still need help?

Email our support team at support@policy-suite.com — we typically respond within 24 hours.

Related Articles