Roles & Permissions
ConcertoGRC uses role-based access control. Each user is assigned a single role that determines what they can see and do within the platform.
Tenant Roles
These roles apply to users within an organization:
| Role | Description |
|---|---|
| Tenant Admin | Full organizational control -- manage all settings, users, data, and configurations |
| Tenant User | Standard read/write access to compliance data -- create and edit records, upload evidence, view reports |
| Tenant Auditor | Read-only access for audit and review purposes -- view and export data, cannot create or edit |
| Tenant Executive | Dashboard-focused access for leadership visibility -- view dashboards and high-level reports |
| Compliance Reviewer | Triage role for customer commitment reviews -- can review and categorize incoming commitments |
| Legal Approver | Approval role for customer commitments -- can approve or reject commitments after compliance review |
Permission Matrix
| Action | Admin | User | Auditor | Executive | Compliance Reviewer | Legal Approver |
|---|---|---|---|---|---|---|
| View dashboards | Yes | Yes | Yes | Yes | Yes | Yes |
| Read all data | Yes | Yes | Yes | Limited | Scoped | Scoped |
| Create/edit records | Yes | Yes | No | No | Scoped | Scoped |
| Delete records | Yes | No | No | No | No | No |
| Generate reports | Yes | No | No | No | No | No |
| Export data | Yes | Yes | Yes | No | Scoped | Scoped |
| Manage users | Yes | No | No | No | No | No |
| Configure settings | Yes | No | No | No | No | No |
| Manage integrations | Yes | No | No | No | No | No |
| Review commitments | Yes | No | No | No | Yes | Yes |
| Approve commitments | Yes | No | No | No | No | Yes |
"Scoped" indicates access is limited to the Customer Commitments module.
Platform Roles
These roles are for Concerto team members who operate the platform:
| Role | Description |
|---|---|
| Concerto Super Admin | Full platform access -- manage all tenants, platform configuration, master frameworks, AI settings |
| Concerto Team | Platform operations -- access tenant data, run migrations, manage integrations |
| Concerto Support | Support access -- view tenant data for troubleshooting, limited write access |
Platform roles can switch between tenant organizations using the organization switcher in the sidebar.
Module-Specific Roles
Some modules have additional role concepts beyond the standard tenant roles:
| Module | Additional Roles |
|---|---|
| Assessments | Audit firm users have separate roles -- Firm Admin and Firm User |
| Tabletop Exercises | Participants with Facilitator, Observer, or Player roles |
Assigning Roles
Tenant administrators manage user roles from Administration > Users. Select a user and update their role in the detail panel. Role changes take effect immediately.
Module Access Roles
Beyond the base tenant role, administrators can create Module Access Roles that control which platform modules a user can see. This allows fine-grained access without changing the user's base role. For example, a Tenant User with a "Security Analyst" Module Access Role might only see Security Operations modules.
Manage Module Access Roles from Administration > Users > Module Access Roles tab.