Understanding user roles and permissions
Prudentia uses role-based access control to govern what each user can see, create, and modify across the platform. Roles are assigned globally per user: a user's role applies consistently across all Assessments they have access to.
There are four roles in Prudentia: Admin, Assessment Owner, Contributor, and Viewer. Roles are managed by Admins and take effect immediately upon assignment.
Admin role
Full platform administrator with complete access to all system functions and every Assessment in the workspace. Admins can invite and manage users and configure global settings. Unlike all other roles, Admins have automatic visibility into every Assessment whether or not they have been explicitly added.
Assessment Owner
Assessment creation and management rights. Assessment Owners can create new Assessments and fully manage any Assessment they own, including adding data sources. They can add users to an Assessment but cannot assign those users' permission levels. They cannot access Assessments they have not been explicitly associated with.
Contributor
Editing access within Assessments they have been added to as a member. Contributors can add comments, change risk scores, and modify impacted parameters. They cannot add data to a project, run or re-run an Assessment, export reports, add users, or create new Assessments.
Viewer
Read-only access to Assessments they have been added to as a member. Viewers can review all project outputs and Assessment results and can leave comments. They cannot create Assessments, add data, edit any content, or export reports.
Permissions at a glance
| Permission | Admin | Owner | Contributor | Viewer |
|---|---|---|---|---|
| View assigned Assessments | ✓ | ✓ | ✓ | ✓ |
| View all workspace Assessments | ✓ | |||
| Leave comments | ✓ | ✓ | ✓ | ✓ |
| Edit risk scores & parameters | ✓ | ✓ | ✓ | |
| Create new Assessments | ✓ | ✓ | ||
| Add data to an Assessment | ✓ | ✓ | ||
| Run / re-run an Assessment | ✓ | ✓ | ||
| Add users to an Assessment | ✓ | ✓ | ||
| Assign global user permissions | ✓ | |||
| Export reports | ✓ | ✓ | ||
| Invite & manage users | ✓ | |||
| Configure global settings | ✓ |