Team and roles
Invite people, what each role can do, and how account activity is recorded.
Guides · 1 min read
Roles
- Owner — full access, including subscription and organisation settings.
- Admin — full compliance work, including approving policies and managing members.
- Member — day-to-day work: upload evidence, work tasks, draft policies.
Only owners and admins can approve a policy. That restriction exists so approval carries authority rather than being a button anyone can press.
Inviting people
Invite by email from Settings. Invitations can be revoked before they're accepted. Removing a member deactivates their access immediately.
Account activity
Security-relevant actions are recorded to an append-only audit trail — invitations, role changes, password changes, policy approvals and revisions, risk changes, framework activation, and connecting or disconnecting an integration. Each entry records who acted, when, and from which address.
More in Guides
Policies and approvalAdopt from templates or write your own, take a policy through review, and keep a versioned approval record.Access reviews and offboardingFind access that should have been removed, and confirm independently that it actually was.Reports and the audit binderReadiness reports, the SOC 2 system description, and a one-click export of everything an auditor asks for.
← All documentation