User Roles and Permissions

Understanding Conformii's role-based access model and how to configure your team.

Role Overview

Conformii uses a role-based access model. The default roles are:

RoleWhat They Can Do
AdministratorFull platform access — configure, edit, delete, manage users
Compliance ManagerView and edit all obligations, run reports, manage the register
Obligation OwnerView and update their assigned obligations, attach evidence
Executive/Read-OnlyView dashboards, status reports and compliance overview
AuditorView all obligations and evidence; cannot edit

Assigning Roles

Roles are assigned by an Administrator from the User Management section of the platform. Each user can have one primary role.

Custom Permissions

For organizations with complex access requirements, custom permission sets can be configured by your success manager. Common customizations include:

  • Restricting obligation visibility to specific facilities or operational areas
  • Allowing certain users to view but not edit specific obligation categories
  • Configuring multi-level approval workflows for evidence submission
  • Best Practices

  • Limit Administrator access to 2–3 people who own the platform configuration
  • Assign Obligation Owner roles broadly — the more people who have visibility into their own obligations, the better the system works
  • Use Auditor roles for external reviewers — they get full visibility without any edit access
  • Set up Executive dashboards early — getting leadership visibility into compliance status is one of the highest-value early wins
  • Managing User Changes

    When personnel change (common in compliance-heavy organizations), update obligation ownership promptly. Obligations with departed owners will show as unassigned and trigger alerts — this is by design.

    Need more help?

    Your Conformii client success manager is available to answer questions, walk through configuration and help you get the most from the platform.