Skip to main content

Roles & Permissions

ConcertoGRC uses role-based access control. Each user is assigned a single role that determines what they can see and do within the platform.

Tenant Roles

These roles apply to users within an organization:

RoleDescription
Tenant AdminFull organizational control -- manage all settings, users, data, and configurations
Tenant UserStandard read/write access to compliance data -- create and edit records, upload evidence, view reports
Tenant AuditorRead-only access for audit and review purposes -- view and export data, cannot create or edit
Tenant ExecutiveDashboard-focused access for leadership visibility -- view dashboards and high-level reports
Compliance ReviewerTriage role for customer commitment reviews -- can review and categorize incoming commitments
Legal ApproverApproval role for customer commitments -- can approve or reject commitments after compliance review

Permission Matrix

ActionAdminUserAuditorExecutiveCompliance ReviewerLegal Approver
View dashboardsYesYesYesYesYesYes
Read all dataYesYesYesLimitedScopedScoped
Create/edit recordsYesYesNoNoScopedScoped
Delete recordsYesNoNoNoNoNo
Generate reportsYesNoNoNoNoNo
Export dataYesYesYesNoScopedScoped
Manage usersYesNoNoNoNoNo
Configure settingsYesNoNoNoNoNo
Manage integrationsYesNoNoNoNoNo
Review commitmentsYesNoNoNoYesYes
Approve commitmentsYesNoNoNoNoYes

"Scoped" indicates access is limited to the Customer Commitments module.

Platform Roles

These roles are for Concerto team members who operate the platform:

RoleDescription
Concerto Super AdminFull platform access -- manage all tenants, platform configuration, master frameworks, AI settings
Concerto TeamPlatform operations -- access tenant data, run migrations, manage integrations
Concerto SupportSupport access -- view tenant data for troubleshooting, limited write access

Platform roles can switch between tenant organizations using the organization switcher in the sidebar.

Module-Specific Roles

Some modules have additional role concepts beyond the standard tenant roles:

ModuleAdditional Roles
AssessmentsAudit firm users have separate roles -- Firm Admin and Firm User
Tabletop ExercisesParticipants with Facilitator, Observer, or Player roles

Assigning Roles

Tenant administrators manage user roles from Administration > Users. Select a user and update their role in the detail panel. Role changes take effect immediately.

Module Access Roles

Beyond the base tenant role, administrators can create Module Access Roles that control which platform modules a user can see. This allows fine-grained access without changing the user's base role. For example, a Tenant User with a "Security Analyst" Module Access Role might only see Security Operations modules.

Manage Module Access Roles from Administration > Users > Module Access Roles tab.