About Compliance Roles
Iru Compliance uses role-based access control. The permissions overview spells out what each role can open or change: search, actions, frameworks (controls and control-linked evidence), artifacts, sources, policies, Trust Center, and related areas. Behavior varies by role. In the tables, Compliance Admin, Compliance Collaborator, and Compliance Auditor sit next to Admin, Standard, and Auditor so you can compare Compliance-only assignments to the same permission pattern. Users with Read activity logs can review compliance and tenant activity on the Unified Activity.Need help with a step? Contact Iru Support.
Access Levels
Admin
Full access to all compliance functionality, including framework management, settings configuration, and administrative controls.Standard
Most of the same permissions as Admin, with limits on framework and settings management.Help Desk
Operational access for day-to-day compliance work, including managing actions, artifacts, and evidence collection.Secrets Auditor
Read-only access with the ability to generate automated artifacts and assess artifact relevance.Auditor
Read-only access for audit and review. In the Frameworks matrix, Auditor does not have View controls (the control definitions in a framework) but does have View control action and View control artifact, so reviewers can still follow actions and evidence tied to controls without editing control definitions. See the matrix for the full list.Iru Support
Read-only access to support customer issues and troubleshooting.Compliance-Only Roles
These roles apply only within Iru Compliance. The Compliance Admin, Compliance Collaborator, and Compliance Auditor columns match Admin, Standard, and Auditor; they do not grant access outside the Compliance area. For tenant-wide roles across Endpoint, Identity, and the rest of the platform, see Team Member Role Permissions.Compliance Admin
Administrator-level access in Iru Compliance only. Matches the Admin column in the permissions overview. This is not tenant-wide Administrator access across products.Compliance Collaborator
Matches the Standard column for team members whose access is limited to Iru Compliance.Compliance Auditor
Matches the Auditor column for team members whose access is limited to Iru Compliance. Under Frameworks, Compliance Auditor behaves like Auditor: no View controls, with View control action and View control artifact for reviews.Permissions Overview
General
Actions
Frameworks
Artifacts
Sources
Policies
Use Compliance → Policies to create, publish, and track acknowledgements for security and compliance policies. See Policies Management for the library, template generation, editor, and workforce acknowledgement flows.
Standard and Compliance Collaborator can create and edit draft policies but cannot publish or delete them, and cannot manage tenant-level policy settings such as owners and categories. Auditor and Compliance Auditor can view published policies and acknowledgement progress but cannot change policy content.
Workforce users are not Compliance administrators. When a policy is published, every user in the tenant sees assignments in My Policies and can acknowledge policies assigned to them. That portal is separate from the Compliance Policies admin view.
Trust Center: Editor
Trust Center: Answers
Trust Center: Artifacts
Trust Center: Accounts
Trust Center: Questionnaires
Common Permission Issues
Use this section when a control is missing or a button has no effect.Cannot add or remove a framework
Cannot add or remove a framework
Only Admin or Compliance Admin can add or remove frameworks. Standard, Compliance Collaborator, and Help Desk cannot.
Cannot open control definitions as Auditor
Cannot open control definitions as Auditor
The Frameworks matrix sets View controls to off for Auditor and Compliance Auditor, while View control action and View control artifact stay on so reviewers can follow actions and evidence without editing control definitions. This is expected.
Cannot edit a control’s definition
Cannot edit a control’s definition
Only Admin or Compliance Admin can edit existing controls. Other roles may add controls or edit control actions only where the Frameworks matrix allows.
Cannot approve control update recommendations
Cannot approve control update recommendations
Iru AI Control Update recommendations (from Home → Insights, Frameworks, or a framework detail page) require permission to approve or reject proposed control and action text. View-only roles may see that a recommendation exists but cannot act on it. See Adaptive Compliance for the review workflow and who can approve changes in your tenant.
Cannot connect or disconnect a source
Cannot connect or disconnect a source
Auditor, Compliance Auditor, and Iru Support cannot manage sources. Use Admin, Compliance Admin, Standard, Compliance Collaborator, or Help Desk as listed under Sources.
Cannot upload artifacts on an action
Cannot upload artifacts on an action
Auditor and Compliance Auditor are read-only for uploads. Use Admin, Compliance Admin, Standard, Compliance Collaborator, Help Desk, or Secrets Auditor as allowed in the Actions table.
Cannot publish or delete a policy
Cannot publish or delete a policy
Only Admin or Compliance Admin can publish or delete policies and manage policy owners and categories. Standard and Compliance Collaborator can create and edit drafts. See the Policies table and Policies Management.
Cannot change Trust Center branding, Answers, or questionnaires
Cannot change Trust Center branding, Answers, or questionnaires
Trust Center Editor, Answers, and Questionnaires changes are Admin or Compliance Admin only unless the matrix shows otherwise.
Related Articles
Getting Started With Compliance
Core concepts and what you can do in Compliance.
Policies Management
Policy library, publishing, and acknowledgements.
Frameworks Management
Who can add or change frameworks by role.
Adaptive Compliance
Approving or rejecting Iru AI control and action updates.
Trust Center Management
External sharing and Trust Center permissions.
Team Member Role Permissions
Tenant-wide roles in Iru (alongside the Compliance roles on this page).