Skip to main content

About Compliance Roles

Iru Compliance uses role-based access control. The permissions overview spells out what each role can open or change: search, actions, frameworks (controls and control-linked evidence), artifacts, sources, policies, Trust Center, and related areas. Behavior varies by role. In the tables, Compliance Admin, Compliance Collaborator, and Compliance Auditor sit next to Admin, Standard, and Auditor so you can compare Compliance-only assignments to the same permission pattern. Users with Read activity logs can review compliance and tenant activity on the Unified Activity.
Need help with a step? Contact Iru Support.

Access Levels

Admin

Full access to all compliance functionality, including framework management, settings configuration, and administrative controls.

Standard

Most of the same permissions as Admin, with limits on framework and settings management.

Help Desk

Operational access for day-to-day compliance work, including managing actions, artifacts, and evidence collection.

Secrets Auditor

Read-only access with the ability to generate automated artifacts and assess artifact relevance.

Auditor

Read-only access for audit and review. In the Frameworks matrix, Auditor does not have View controls (the control definitions in a framework) but does have View control action and View control artifact, so reviewers can still follow actions and evidence tied to controls without editing control definitions. See the matrix for the full list.

Iru Support

Read-only access to support customer issues and troubleshooting.

Compliance-Only Roles

These roles apply only within Iru Compliance. The Compliance Admin, Compliance Collaborator, and Compliance Auditor columns match Admin, Standard, and Auditor; they do not grant access outside the Compliance area. For tenant-wide roles across Endpoint, Identity, and the rest of the platform, see Team Member Role Permissions.

Compliance Admin

Administrator-level access in Iru Compliance only. Matches the Admin column in the permissions overview. This is not tenant-wide Administrator access across products.

Compliance Collaborator

Matches the Standard column for team members whose access is limited to Iru Compliance.

Compliance Auditor

Matches the Auditor column for team members whose access is limited to Iru Compliance. Under Frameworks, Compliance Auditor behaves like Auditor: no View controls, with View control action and View control artifact for reviews.

Permissions Overview

General

Actions

Frameworks

Artifacts

Sources

Policies

Use Compliance → Policies to create, publish, and track acknowledgements for security and compliance policies. See Policies Management for the library, template generation, editor, and workforce acknowledgement flows. Standard and Compliance Collaborator can create and edit draft policies but cannot publish or delete them, and cannot manage tenant-level policy settings such as owners and categories. Auditor and Compliance Auditor can view published policies and acknowledgement progress but cannot change policy content. Workforce users are not Compliance administrators. When a policy is published, every user in the tenant sees assignments in My Policies and can acknowledge policies assigned to them. That portal is separate from the Compliance Policies admin view.

Trust Center: Editor

Trust Center: Answers

Trust Center: Artifacts

Trust Center: Accounts

Trust Center: Questionnaires

Common Permission Issues

Use this section when a control is missing or a button has no effect.
Only Admin or Compliance Admin can add or remove frameworks. Standard, Compliance Collaborator, and Help Desk cannot.
The Frameworks matrix sets View controls to off for Auditor and Compliance Auditor, while View control action and View control artifact stay on so reviewers can follow actions and evidence without editing control definitions. This is expected.
Only Admin or Compliance Admin can edit existing controls. Other roles may add controls or edit control actions only where the Frameworks matrix allows.
Iru AI Control Update recommendations (from HomeInsights, Frameworks, or a framework detail page) require permission to approve or reject proposed control and action text. View-only roles may see that a recommendation exists but cannot act on it. See Adaptive Compliance for the review workflow and who can approve changes in your tenant.
Auditor, Compliance Auditor, and Iru Support cannot manage sources. Use Admin, Compliance Admin, Standard, Compliance Collaborator, or Help Desk as listed under Sources.
Auditor and Compliance Auditor are read-only for uploads. Use Admin, Compliance Admin, Standard, Compliance Collaborator, Help Desk, or Secrets Auditor as allowed in the Actions table.
Only Admin or Compliance Admin can publish or delete policies and manage policy owners and categories. Standard and Compliance Collaborator can create and edit drafts. See the Policies table and Policies Management.
Trust Center Editor, Answers, and Questionnaires changes are Admin or Compliance Admin only unless the matrix shows otherwise.
If controls or actions look wrong for your access level, open the Access page to confirm your role (Account Menu ButtonAccess).

Getting Started With Compliance

Core concepts and what you can do in Compliance.

Policies Management

Policy library, publishing, and acknowledgements.

Frameworks Management

Who can add or change frameworks by role.

Adaptive Compliance

Approving or rejecting Iru AI control and action updates.

Trust Center Management

External sharing and Trust Center permissions.

Team Member Role Permissions

Tenant-wide roles in Iru (alongside the Compliance roles on this page).