Assigning Policy and Compliance Management roles to your users
Before you can successfully implement or use the Policy and Compliance Management application, you must assign roles to your users.
Before you begin
Role required: admin
Procedure
Navigate to All > User Administration > Users.
Click the name of a user.
Click the Roles tab.
Click Edit.
Move the roles you want to assign to the user from the Collection side to the Roles List, then click Save.
Repeat these steps for each of your users.
For a comprehensive list of compliance users, see Roles installed with GRC: Policy and Compliance Management.
| Role title \[name\] | Description |
|---|---|
| Compliance Reader\[sn\_compliance.reader\] | The Compliance Reader has read-only access to all modules of the Policy and Compliance Management application. This role is typically assigned to users who need to see what policies and controls are within the organization. Users with the reader role are also often responsible for reporting and monitoring activities. The Compliance Reader role contains: sn\_grc.reader. |
| Compliance User\[sn\_compliance.user\] | The Compliance User, often referred to as the Compliance Analyst, has permissions enough to fulfill virtually any policy- or control-related task. Users assigned this role are often responsible for:
|
| Compliance Manager\[sn\_compliance.manager\] | The Compliance Manager is responsible for managing the day-to-day compliance process. Users assigned this role are often responsible for: - Reviewing specific regulatory requirements and trends - Determining which regulations require a policy - Approving policies and policy exceptions - Setting up a policy acknowledgement campaign - Scoping controls using entity types and entities - Creating and assigning attestations - Continuously monitoring control effectiveness - Compiling and sharing reports highlighting data, such as non-compliant controls The Compliance Manager role contains: - sn\_grc.reader - sn\_grc.user - sn\_grc.manager - sn\_compliance.reader - sn\_compliance.user |
| Compliance Administrator\[sn\_compliance.admin\] | The Compliance Administrator administers the Policy and Compliance Management application. Users assigned this role are often responsible for: - Monitoring platform dependencies with other applications and modules - Controlling all compliance data The Compliance Administrator role contains: - sn\_grc.reader - sn\_grc.user - sn\_grc.manager - sn\_grc.admin - sn\_compliance.reader - sn\_compliance.user - sn\_compliance.manager |
| Compliance Developer\[sn\_compliance.developer\] | The Compliance Developer is responsible for maintaining various aspects of the platform, such as creating workflows, reports, dashboards, additional modules, and other platform-specific content that can enrich the application.The Compliance Developer role contains: - sn\_grc.reader - sn\_grc.user - sn\_grc.manager - sn\_grc.admin - sn\_grc.developer - sn\_compliance.reader - sn\_compliance.user - sn\_compliance.manager - sn\_compliance.admin |
| Attestation Creatorsn\_compliance.attestation\_creator | The Attestation Creator is responsible for creating and maintaining attestations. Attestations are one of the platform components used to attest controls and it is essential for keeping them lean, precise, and up-to-date. |
What to do next
Return to the Policy and Compliance Management setup checklist.
Parent Topic:Perform Policy and Compliance Management administration