AI Control Tower roles
Certain roles are installed along with the installation of the AI Control Tower.This section also covers roles which are installed with AI Risk and Compliance.
| Role title \[name\] | Description | Contains roles |
|---|---|---|
| AI steward\[sn\_ai\_governance.ai\_steward\] | Note: The organization decides on assigning the AI steward role. By adding the users to the AI stewards group, allows user to have additional permissions related to playbook. The AI steward is responsible for:
For AI discovery:
For AI Gateway:
| - sn\_nowassist\_admin.user - sn\_ai\_governance.workspace\_admin - sn\_aia.admin - aig\_admin - sn\_mcp\_client.admin - sn\_align\_core.apw\_user- Can create, update, and delete portfolio plans, free-form road maps, and planning items - it\_demand\_manager- User who manages the inflow, screening and facilitates the prioritization of IT demands - it\_project\_manager- User of the project management application, and manager of IT projects - sn\_apw\_advanced.pf\_user- Can create, view, update, and delete the Product Feedback records |
| AI asset owner \[sn\_ai\_asset\_mgmt.ai\_asset\_owner\] | The AI asset owner is responsible for:
| None |
AI AI Risk and Compliance roles
The AI Risk and Compliance application installs the essential role to perform respective day-to-day operational tasks for managing AI systems across the enterprise.
| Role title \[name\] | Description | Contains roles |
|---|---|---|
| AI Risk and Compliance Admin \[sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_admin\] | The AI Risk and Compliance Admin can perform the following tasks:- Set up risk and impact assessment frameworks. Configure risk assessment methodologies, risk contribution factors, and impact assessment templates - Define automation rules for impact assessments to determine applicable risks and controls based on the assessment responses - Set up and profile AI case types - Delete AI systems. - Enable or disable Entity-Based Access for record types associated with entity properties, and configure the Entity-Based Access settings as needed. Note: GRC: Entity Based Access application must be installed to use this feature |
Note: GRC: Entity Based Access application must be installed for this role to be available. |
| AI Risk and Compliance Manager \[sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_manager\] | The AI Risk and Compliance Manager can access all AI systems on the system and perform the following tasks:- Initiate impact assessments - Manage the life cycle of an AI system - Initiate risk assessments - Initiate control attestations - Write and update access to the bulk access update configuration. Note: GRC: Entity Based Access application must be installed to use this feature. |
Note: GRC: Entity Based Access application must be installed for this role to be available. |
| AI Risk and Compliance Analyst \[sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_analyst\] | The AI Risk and Compliance Analyst can access all AI systems assigned to them in the system and perform the following tasks only on the assigned records:- Initiate impact assessments - Manage the life cycle of an AI system - Initiate risk assessments - Initiate control attestations | - sn\_ai\_case\_mgmt.ai\_case\_analyst - sn\_smart\_asmt.assessment\_reader - sn\_smart\_asmt.template\_reader - sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_business\_user - sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_reader - sn\_grc\_workspace.user - sn\_grc\_workspace.state\_model\_reader - sn\_risk\_advanced.ara\_creator - sn\_risk\_advanced.ara\_assessor - sn\_risk\_advanced.ara\_approver - sn\_risk\_advanced.risk\_asmt\_project\_user |
| AI Risk and Compliance Business User \[sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_business\_user\] | The AI Risk and Compliance User can perform the following tasks:- Create AI case on the Employee Center - Work on the assigned tasks - Perform control attestations | - sn_grc_workspace.assessment_template_configuration_reader - sn_smart_asmt.actor - sn_grc_workspace.user - sn_smart_asmt.assessment_reader - sn_risk_advanced.risk_asmt_project_reader Note: For more information on AI Control Tower roles, see AI Control Tower roles. |
| AI Risk and Compliance Reader \[sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_reader\] | The AI Risk and Compliance Reader can have read access to the AI systems and AI impact assessments. | - sn\_grc\_workspace.user - sn\_grc\_workspace.state\_model\_reader |
| AI System Reader \[sn\_grc\_ai\_gov.ai\_risk\_and\_compliance\_ai\_system\_reader\] | The AI System Reader can have read access to the AI systems on AI Control Tower workspace and AI Risk and Compliance workspace. | NA |
| AI Case Business User \[sn\_ai\_case\_mgmt.ai\_case\_business\_user\] | The AI Case Business User can create AI case and AI inquiry on the Employee Center. | sn\_grc\_case\_mgmt.grc\_case\_business\_user |
| AI Case Analyst \[sn\_ai\_case\_mgmt.ai\_case\_analyst\] | The AI Case Analyst can review the AI cases and AI inquiries assigned to them in the system and perform the following tasks only on the assigned records:- Identify and manage impacted and related areas such as policies, regulations, and enterprise-wide compliance risks - Identify and manage issues related to impacted areas to eliminate the root causes | - sn\_grc\_case\_mgmt.grc\_case\_analyst - sn\_ai\_case\_mgmt.ai\_case\_business\_user |
| AI Case Manager \[sn\_ai\_case\_mgmt.ai\_case\_manager\] | The AI Case Manager can review all the AI cases, AI inquiries, and its associated information. | - sn\_ai\_case\_mgmt.ai\_case\_analyst - sn\_grc\_case\_mgmt.grc\_case\_manager |
| AI Case Admin \[sn\_ai\_case\_mgmt.ai\_case\_admin\] | The AI Case Admin can manage type profiles to segregate AI cases. They can set up assignment rules and delete AI cases. | - sn\_grc\_case\_mgmt.grc\_case\_admin - sn\_ai\_case\_mgmt.ai\_case\_manager |