Access Control permissions by role and by action

The Access Control page lets users manage Access Control Groups, the companies in each group, and the users assigned to each group. A user's role determines which of these actions the user can do. This article lists the Access Control permissions for each role and for each action.

Roles referenced on this page: Users with the Admin, Group Admin, Portfolio Manager, Internal Business User, Operations, User, or View Only role.

What can my role do?

Use this section to find everything a specific role can and can't do on the Access Control page. For a breakdown by action instead, see By action below.

What can an Admin do on the Access Control page?
  • Can add and remove companies in any group.
  • Can create and delete Access Control Groups.
  • Can allocate subscriptions to a group and set the flexibility given to Group Admins and Portfolio Managers.
  • Can set access to rating bundles for a group.
  • Can set company details (tiers, life cycles, relationships) as global or group-level access.
  • Can set the default group that new users join.
  • Can assign users to a group.
  • Can create, edit, and delete users, and resend activation emails.
What can a Group Admin do on the Access Control page?
  • Can remove companies from their own group.
  • Cannot add companies to a group.
  • Cannot create, delete, or otherwise manage Access Control Groups.
  • Cannot assign users to a group.
  • Can edit users within their own group.
  • Cannot create users, delete users, or resend activation emails.
What can a Portfolio Manager do on the Access Control page?
  • Can remove companies from their own group.
  • Cannot add companies to a group.
  • Cannot create, delete, or otherwise manage Access Control Groups.
  • Cannot assign users to a group.
  • Cannot create, edit, or delete users, or resend activation emails.
What can an Operations user do on the Access Control page?
  • Cannot add or remove companies in a group.
  • Cannot create, delete, or otherwise manage Access Control Groups.
  • Assigning users to a group does not apply to this role.
  • Cannot create, edit, or delete users, or resend activation emails.
What can an Internal Business Users do on the Access Control page?
  • Cannot add or remove companies in a group.
  • Cannot create, delete, or otherwise manage Access Control Groups.
  • Assigning users to a group does not apply to these roles.
  • Creating, editing, or deleting users does not apply to these roles.
What can a User do on the Access Control page?
  • Cannot add or remove companies in a group.
  • Cannot create, delete, or otherwise manage Access Control Groups.
  • Cannot assign users to a group.
  • Cannot create, edit, or delete users, or resend activation emails.
What can a View Only user do on the Access Control page?
  • Cannot add or remove companies in a group.
  • Cannot create, delete, or otherwise manage Access Control Groups.
  • Assigning users to a group does not apply to these roles.
  • Creating, editing, or deleting users does not apply to these roles.

By action

Permissions key

✅ = Is permitted.

❌ = Not permitted.

➖ = Not applicable and not permitted.

View companies and findings

All roles can do this.
 

Create and share folders

All roles can do this.
 

Download or export documents

All roles can do this.
 

Submit support tickets

All roles can do this.
 

Add companies to a portfolio

✅ Admins can add companies to any portfolio. 

✅ Group Admins and Portfolio Managers can add companies to their own group's portfolio only. 

❌ All other roles cannot add companies to a portfolio.
 

Create or modify users

✅ Admins can create or modify any user. 

✅ Group Admins can create or modify users within their own group only. 

❌ All other roles cannot create or modify users.
 

Remove users

✅ Admins can remove any user. 

✅ Group Admins can remove users within their own group only. 

❌ Portfolio Managers and Users cannot remove users.
 

Remove companies from 
a portfolio

✅ Admins can remove companies from any portfolio. 

✅ Group Admins can remove companies from their own group's portfolio only. 

❌ Portfolio Managers and Users cannot remove companies from a portfolio.
 

Create or modify Access 
Control Groups

✅ Only Admins can do this.

❌ No other role can create or modify Access Control Groups.
 

Modify group limits

✅ Only Admins can do this.

❌ No other role can modify group limits.
 

Modify distribution 
list settings

✅ Only Admins can do this.

❌ No other role can modify distribution list settings.
 

Delegate portfolio 
management

✅ Only Admins can do this.

❌ No other role can delegate portfolio management.
 

Publish Date or Recent Edits
  • November 22, 2024: Separated from User Permissions and added VRM/TMH roles.
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.