Workspace roles & permissions
Every person in a Govern365 workspace has exactly one of four roles: Admin, Editor, Reviewer, and Auditor.
This page is the overview. Feature guides (frameworks, projects, models, risks, evidence, etc.) spell out screen-by-screen behaviour; when they say “Admin or Editor”, they mean these roles.
The four roles (at a glance)
| Role | Typical use |
|---|---|
| Admin | Full workspace control: billing/team where exposed, destructive actions (e.g. delete framework, delete project, production lifecycle steps), and everything Editors can do for day-to-day governance data. |
| Editor | Create and edit governance content: projects, frameworks, models, org risks, evidence uploads, most controls—without some Admin-only destructive or lifecycle transitions. |
| Reviewer | Read the workspace and, where the product allows it, approve or reject work in review (for example AI project lifecycle when a project is Under review). Usually no create/delete for heavy artefacts unless a screen says otherwise. |
| Auditor | Read-focused: browse dashboards, registers, frameworks, and evidence; use Download where offered. Upload, edit, or delete are generally hidden. |
Exact buttons can differ by area — always check the guide for that screen.
Where your role comes from
- First admin — The person who signs up or creates the workspace is an Admin for that organization.
- Invitations — Invites specify a role (Admin, Editor, Reviewer, or Auditor). See First-time onboarding (invite step) and Accept a workspace invitation.
- Later changes — An Admin can update a member’s role in Team settings.
Common patterns in the app
Two roles can edit content (most places)
Many features allow Admin or Editor to create, upload, or save, while Reviewer and Auditor browse or download only. Examples: Evidence & documents, Risk register, much of Framework setup.
Admin-only actions
Examples include deleting certain resources, some model status transitions, moving an AI project to production or retired, and removing members / changing roles in team settings.
Reviewer-specific
AI projects documents when a Reviewer may Approve or Reject a project in Under review status (project lifecycle). Pending approvals documents Reviewer or Admin approve/reject on approval requests (separate workflow).
Related help
- Pending approvals — approval request queue and who can approve.
- First-time onboarding — assigning roles when inviting from the setup wizard.
- Accept a workspace invitation — joining with the role your admin chose.
- Dashboard — what you see still depends on data and cards; your role controls edits, not the card list itself.
- AI projects — lifecycle and role matrix for projects.
- Framework setup — who can edit programs, controls, and risks.
- Model registry — registry, detail, and delete rules by role.
- Evidence & documents — upload and folder rules by role.
- Risk register — organisation risk register by role.
- Tasks — who can create and complete tasks.
- Governance Flow — read-only map; editing happens on the underlying records.