Skip to content
Documentation

Roles and permissions

How workspace access works for owners, members, and custom roles.

Access in RiskCurb follows the workspace. Members of a team account see the register and work in it according to their role. People who are not members of the workspace do not see its data.

Owner

Owners have full access to the workspace: member management, billing, and all workspace data. Keep ownership to one or two people, typically the risk manager and a deputy. Ownership can be transferred when roles change.

Member

Members have day-to-day access: creating and editing risks, updating controls and treatments, logging claims, and viewing reports. Most of the team are members. What a member can change is also bounded by ownership, since reviews and treatments route to their assigned owners.

Custom roles

Many agencies separate duties. A read-only audit role, a claims-only role for the claims team, or a departmental role scoped to one service area are common patterns. Custom roles carry the specific permissions you define for them, so people see what their job requires and no more.

Permissions and the register

Ownership is the second layer of access. A department lead who is a member sees the register, but the risks that route to them for review and treatment are the ones they own. Ownership drives the workflow: reviews, overdue items, and approvals find their person.

Practical hygiene

  • Review the member list when staff change, and remove departing members promptly.
  • Reassign ownership of their risks in the same motion, so nothing sits unowned.
  • Audit who holds owner and custom roles once a year. Access drift is a risk of its own.

See Data and security for how access is enforced technically.