Roles and Permissions
About roles and permissions
Section titled “About roles and permissions”A role is the position a user is assigned within Governance Studio.
Permissions are actions a user is granted based on their role.
Key concepts and actions associated with roles and permissions include:
Understanding roles
Section titled “Understanding roles”There are seven project and compliance roles in Governance Studio, each designed to support specific functions within your compliance workflow, plus an organization-level Agent Operator role for agent enrollment.
Organization Owner
- Role Description: Manages organization-wide settings, users, indicators, and policies, with full administrative control across all projects
- Typical Personas: Chief Compliance Officer, VP of Engineering, Head of GRC
Agent Operator
- Role Description: Registers gateway agents for the organization. Does not administer users, policies, or project membership
- Typical Personas: Platform Engineer, CI Owner, Fleet Operator
Project Owner
- Role Description: Manages a project’s configuration and membership, including applied policies, indicators, declarations, reviews, and credentials
- Typical Personas: Engineering Manager, Product Manager, Compliance Manager
Implementation Owner
- Role Description: Creates declarations and submits controls for review
- Typical Personas: Senior Engineer, Tech Lead, Compliance Analyst
Implementation Contributor
- Role Description: Creates declarations, but cannot submit controls for review
- Typical Personas: Junior Engineer, Compliance Associate
Audit Owner
- Role Description: Creates comments, determines compliance outcomes, and issues policy credentials
- Typical Personas: Head of Compliance, Chief Auditor, Internal Audit Director
Audit Contributor
- Role Description: Creates comments, but cannot determine compliance outcomes
- Typical Personas: Junior Auditor, Internal Auditor, Compliance Reviewer
Project Viewer
- Role Description: Read-only access to project data; cannot create or modify resources
- Typical Personas: Executive Stakeholder, External Auditor, Board Member
Understanding permissions
Section titled “Understanding permissions”Manage Organization Settings
- Permissions Definition: Manage organization-wide settings and preferences
Manage Organization Users
- Permissions Definition: Add and remove users, and assign roles within the organization
Register Agents
- Permissions Definition: Register gateway agents under your account
Create Agent Memberships
- Permissions Definition: Associate a registered agent with a project
Create Projects
- Permissions Definition: Create projects within the organization
Archive Projects
- Permissions Definition: Archive projects within the organization
Manage Project Members
- Permissions Definition: Add and remove project members, and assign roles within the project
Create Policies
- Permissions Definition: Create or upload policies for the organization
Apply Policies to Projects
- Permissions Definition: Apply a policy to a project
Archive Applied Policies
- Permissions Definition: Archive policies applied to projects
Create Credentials
- Permissions Definition: Issue credentials for an applied policy
Revoke Credentials
- Permissions Definition: Revoke an issued credential for an applied policy
Create Indicators
- Permissions Definition: Create an indicator for a project
Archive Indicators
- Permissions Definition: Archive an indicator within a project
Apply Indicators
- Permissions Definition: Apply an indicator to an applied policy’s control
Activate Indicators
- Permissions Definition: Activate applied indicators so they log evaluations
Disable Indicators
- Permissions Definition: Disable applied indicators so they do not log evaluations
Run Indicators
- Permissions Definition: Run indicators to receive and log evaluations
Create Declarations
- Permissions Definition: Submit a declaration to a control
Submit Controls for Review
- Permissions Definition: Submit a control as ready for review
Determine Control Outcomes
- Permissions Definition: Determine a control as Compliant, Non-compliant, or Not Applicable
Create Comments
- Permissions Definition: Submit a comment to a control
Export PDF Report
- Permissions Definition: Export a PDF report bundle for an applied policy
View Project Data
- Permissions Definition: View project data (read-only access)
Role and permissions matrix
Section titled “Role and permissions matrix”Each role is composed of specific permissions as shown in the table below.
A check (✅) indicates the role has this permission, while an X (❌) indicates it does not.
Manage Organization Settings
- Organization Owner: ✅
- Project Owner: ❌
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Manage Organization Users
- Organization Owner: ✅
- Project Owner: ❌
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Register Agents
- Organization Owner: ✅
- Project Owner: ❌
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Create Agent Memberships
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Create Projects
- Organization Owner: ✅
- Project Owner: ❌
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Archive Projects
- Organization Owner: ✅
- Project Owner: ❌
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Manage Project Members
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Create Policies
- Organization Owner: ✅
- Project Owner: ❌
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Apply Policies to Projects
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Archive Applied Policies
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Create Credentials
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ✅
- Audit Contributor: ❌
- Project Viewer: ❌
Revoke Credentials
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ✅
- Audit Contributor: ❌
- Project Viewer: ❌
Create Indicators
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Archive Indicators
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Apply Indicators
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Activate Indicators
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Disable Indicators
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Run Indicators
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ✅
- Implementation Contributor: ✅
- Audit Owner: ✅
- Audit Contributor: ✅
- Project Viewer: ❌
Create Declarations
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ✅
- Implementation Contributor: ✅
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Submit Controls for Review
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ✅
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
Determine Control Outcomes
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ✅
- Audit Contributor: ❌
- Project Viewer: ❌
Create Comments
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ✅
- Audit Contributor: ✅
- Project Viewer: ❌
Export PDF Report
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ❌
- Implementation Contributor: ❌
- Audit Owner: ❌
- Audit Contributor: ❌
- Project Viewer: ❌
View Project Data
- Organization Owner: ✅
- Project Owner: ✅
- Implementation Owner: ✅
- Implementation Contributor: ✅
- Audit Owner: ✅
- Audit Contributor: ✅
- Project Viewer: ✅
Agent Operator is assigned on the organization rather than on a project, so it is not a column in the matrix above. It grants Register Agents and View Project Data, so an operator can enroll agents and use Governance Studio. It does not grant Create Agent Memberships — associating an agent with a project stays with the Project Owner or Organization Owner. Organization Owners already have Register Agents.
Assign Agent Operator to people who should enroll agents without administering the organization. See Register Agents.
Managing user roles
Section titled “Managing user roles”Assigning the right roles ensures users have appropriate access to perform their compliance work while maintaining security and separation of duties.
Organization Owners can assign roles to all users across projects. Project Owners can only assign roles within projects they manage.
When assigning roles, consider:
- Separation of duties: Implementation and audit roles are designed to maintain independence between those who implement controls and those who review them
- Junior team members: Contributor roles allow junior staff to participate without actioning definitive compliance outcomes
- Multiple roles: Users can be assigned multiple roles within a single project and/or across multiple projects