Trust Management Hub & Vendor Risk Management Data permissions by role and by action

Trust Management Hub and Vendor Risk Management hold third party risk management data, including artifacts, assignments, vendor connections, findings, reports, and security profiles. A user's Trust Management Hub or Vendor Risk Management role determines who can access and manage each type of data. For role descriptions, see Vendor Risk Management and Trust Management Hub user roles. This article lists the permissions for each role and for each action.

Roles referenced on this page: Users with the Admin, Group Admin, Portfolio Manager, Operations, Internal Business User, User, View Only, TMH Access Only Operations, Sales, or Sales Operations role.

What can my role do?

Use this section to find everything a specific role can and can't do with Trust Management Hub and Vendor Risk Management data. For a breakdown by action instead, see By action below.

What can an Admin do with Trust Management Hub and Vendor Risk Management data?
  • Can do every action listed in this article.
What can a Group Admin do with Trust Management Hub and Vendor Risk Management data?
  • Trust Management Hub and Vendor Risk Management data permissions do not apply to this role.
What can a Portfolio Manager do with Trust Management Hub and Vendor Risk Management data?
  • Trust Management Hub and Vendor Risk Management data permissions do not apply to this role.
What can an Operations user do with Trust Management Hub and Vendor Risk Management data?
  • Can download artifacts.
  • Can assign tasks, edit assignments, and view tasks.
  • Can access connections and establish connections.
  • Can access the Executive Summary and the Trust Management Hub dashboard.
  • Can create findings and view findings.
  • Can generate the Findings Overview report and the Risk Assessment Summary report.
  • Can share your security profile.
  • Cannot edit company information.
What can an Internal Business User do with Trust Management Hub and Vendor Risk Management data?
  • Can download artifacts of assigned vendors.
  • Can view tasks they own.
  • Can access connections for assigned vendors only.
  • Can create findings and view findings. [Confirm the scope. The current article describes both actions as "download artifacts of assigned vendors."]
  • Cannot assign tasks, edit assignments, or establish connections.
  • Cannot edit company information.
  • Cannot access the Executive Summary or the Trust Management Hub dashboard.
  • Cannot generate the Findings Overview report or the Risk Assessment Summary report.
  • Sharing your security profile does not apply to this role.
What can a User do with Trust Management Hub and Vendor Risk Management data?
  • Trust Management Hub and Vendor Risk Management data permissions do not apply to this role.
What can a View Only user do with Trust Management Hub and Vendor Risk Management data?
  • Can download artifacts.
  • Can view tasks they own.
  • Can access connections.
  • Can access the Executive Summary.
  • Can view findings.
  • Can generate the Findings Overview report and the Risk Assessment Summary report.
  • Can share your security profile.
  • Cannot assign tasks, edit assignments, or establish connections.
  • Cannot edit company information.
  • Cannot use the Trust Management Hub dashboard.
  • Cannot create findings.
What can a TMH Access Only Operations user do with Trust Management Hub and Vendor Risk Management data?
  • Can view and use the Trust Management Hub dashboard.
  • Cannot edit company information.
  • Cannot access the Executive Summary.
  • [Confirm the permissions for every other action. The current article lists this role for the actions shown here only.]
What can a Sales user do with Trust Management Hub and Vendor Risk Management data?
  • Can share your security profile.
  • [Confirm the permissions for every other action. The current article lists this role for the actions shown here only.]
What can a Sales Operations user do with Trust Management Hub and Vendor Risk Management data?
  • Can share your security profile.
  • [Confirm the permissions for every other action. The current article lists this role for the actions shown here only.]

By action

Permissions key

✅ = Is permitted.

❌ = Not permitted.

➖ = Not applicable and not permitted.

Download artifacts

✅ Admins, Operations, and View Only can do this.

✅ Internal Business Users can download artifacts of assigned vendors only.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.

Good to know: artifacts are third party risk management documentation requested from the third party being assessed.
 

Assign tasks

✅ Admins and Operations can do this.

❌ Internal Business Users and View Only cannot do this.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.
 

Edit assignments

✅ Admins and Operations can do this.

❌ Internal Business Users and View Only cannot do this.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.
 

View tasks

✅ Admins and Operations can view all tasks.

✅ Internal Business Users and View Only can view owned tasks only.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.
 

Access connections with 
vendors

✅ Admins, Operations, and View Only can do this.

✅ Internal Business Users can access connections for assigned vendors only.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.
 

Request a connection with a 
vendor

✅ Admins and Operations can do this.

❌ Internal Business Users and View Only cannot do this.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.
 

Edit company information

✅ Only Admins can do this.

❌ Internal Business Users, Operations, TMH Access Only Operations, and View Only cannot do this.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.
 

Access the Executive 
Summary page

✅ Admins, Operations, and View Only can do this.

❌ Internal Business Users and TMH Access Only Operations cannot do this.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.
 

View and use the TMH 
Dashboard

✅ Admins, Operations, and TMH Access Only Operations can do this.

❌ Internal Business Users and View Only cannot do this.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.
 

Create findings

✅ Admins, Operations, and Internal Business Users can do this. [Confirm the Internal Business User scope.]

❌ View Only cannot do this.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.

Good to know: findings are questions or concerns sent to the third party being assessed, including an expected remediation plan or outcome.
 

Generate the Findings 
Overview report

✅ Admins, Operations, and View Only can do this.

❌ Internal Business Users cannot do this.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.

Good to know: the Findings Overview report summarizes the findings identified during vendor assessment.
 

View findings

✅ Admins, Operations, Internal Business Users, and View Only can do this. [Confirm the Internal Business User scope.]

➖ Not applicable to Group Admins, Portfolio Managers, and Users.
 

Generate the Risk 
Assessment Summary report

✅ Admins, Operations, and View Only can do this.

❌ Internal Business Users cannot do this.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.

Good to know: the Risk Assessment Summary report shows a view of vendor security and risk posture.
 

Share your security profile

✅ Admins, Operations, Sales, Sales Operations, and View Only can do this.

➖ Not applicable to Internal Business Users, Group Admins, Portfolio Managers, and Users.
 

Publish Date or Recent Edits
  • July 3, 2025: Assignments.
  • March 24, 2025: Risk Assessment Summary and Findings Overview report permissions.
  • January 3, 2025: Share your security profile; Access the Dashboard in the TMH app; Executive Summary; Edit company information.
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.