Appearance
User Roles & Permissions
OrviQ employs Role-Based Access Control (RBAC) to enforce Segregation of Duties (SoD) and ensure users only access and modify data aligned with their governance responsibilities.
Standard User Roles
1. Compliance Manager
- Primary Domain: Regulatory Compliance, Policy Governance, Work & Decisions
- Responsibilities:
- Ingest and scope regulatory frameworks.
- Approve crosswalk mappings and compliance determinations.
- Author and review corporate policies.
- Sign off on compliance reviews.
2. Risk Manager
- Primary Domain: Risk Management, Incidents & Loss Events
- Responsibilities:
- Maintain the enterprise risk register and methodology.
- Review and triage compliance findings.
- Evaluate and recommend risk treatment strategies.
- Oversee RCSA campaigns and review exception requests.
3. Control Owner / Contributor
- Primary Domain: Controls & Assurance, Work & Decisions
- Responsibilities:
- Implement and maintain internal control procedures.
- Upload verified evidence artifacts to the Evidence Fabric.
- Perform self-assessments and respond to testing requests.
- Execute assigned remediation action plan milestones.
4. Internal / External Auditor
- Primary Domain: Audit & Inspection, Controls & Assurance (Read-Only)
- Responsibilities:
- Plan audit engagements and define testing sample populations.
- Inspect control design adequacy and operating effectiveness.
- Log audit findings and request supervisory documentation.
- Access immutable audit logs and historical snapshots.
5. Read-Only Stakeholder
- Primary Domain: Home, Reports
- Responsibilities:
- Review executive dashboards and posture reports.
- Inspect published policies and public framework mappings.
- Cannot perform state transitions or modify records.
6. Tenant Administrator
- Primary Domain: Administration
- Responsibilities:
- Manage user accounts, role assignments, and organizational units.
- Configure AI Provider integrations and BYO API keys.
- Define workflow approval chains (maker-checker, 4-eye).
- Set SLA deadline policies and breach notification rules.
Role Entitlements Overview
| Capability | Tenant Admin | Compliance Manager | Risk Manager | Control Owner | Auditor | Read Only |
|---|---|---|---|---|---|---|
| User & Role Management | Yes | No | No | No | No | No |
| AI Provider Configuration | Yes | No | No | No | No | No |
| Framework Scoping & Determinations | Yes | Yes | No | No | Read | Read |
| Control & Mapping Management | Yes | Yes | Read | Yes | Read | Read |
| Evidence Upload & Verification | Yes | Yes | Yes | Yes | Read | Read |
| Risk & Finding Governance | Yes | Read | Yes | Contributor | Read | Read |
| Audit Engagements & Workpapers | Yes | Read | Read | Contributor | Yes | Read |
| Executive Reports & Dashboards | Yes | Yes | Yes | Yes | Yes | Yes |