User Roles

IRM supports the following user roles with different permissions in the system: Admin, DPO, Participant, Auditor, and CPO.

 

Admin User Role

Admins within a customer account can configure the IRM system. They can set up intake forms, configure assignees, etc. In addition, they are able to view and process all requests in the system. This role is usually granted to managers overseeing Data Privacy Officers (DPOs) and Admins helping to set up the system. This role should be granted with caution due to the amount of control it grants.

 

DPO User Role

DPOs within a customer account can view and process requests assigned to them. They are not able to configure the IRM system. This role, as the name suggests, should be granted to Data Privacy Officers who manage requests on a day-to-day basis.

 

Participant Role

The participant role should be granted to all stakeholders who will be working with DPOs on completing a request. In a typical organization, this usually includes, but is not limited to, IT System Administrators, Marketing, Human Resources, etc.

Once assigned this role, Participants within a customer account can view a request only if they have been commented at with an @-mention within the comments section of that request. Once they include an @-mention, they can upload attachments related to fulfilling the request. But they cannot view attachments uploaded by others to the same request. 

Participants cannot view the request even if they can view the tasks and subtasks assigned to them. If the parent tasks are assigned to them, they can view the subtasks regardless of whether or not the subtasks are assigned to them.

Participants cannot process a request for completion.

 

Auditor Role

This role, as the name suggests, should be granted to Auditors who check for compliance to required rules such as GDPR and CCPA. Auditors within a customer account can view all requests and download request metadata. They are not able to configure the IRM system, upload attachments to requests, comment on requests, or process requests.

 

CPO Role

A user with a CPO or Chief Privacy Officer role can access the Request page (all requests) and the My task page (request’s task/sub task). Although this role cannot access the Admin menu, like any admin user, it can be assigned to requests and they would be able to accept or reject  requests and perform other request operations.

 

Support Role

A user with the Support role can ONLY see the requests that they are assigned to. This role cannot accept or reject requests.

The below chart details the permissions that various users have in the IRM platform for a given account:

 

 OperationsAdminDPOAuditorParticipantCPOSupport

Requests
ViewOwn AccountAssigned to Task / Requests / MentionedOwn AccountAssigned to Task / MentionedOwn AccountAssigned to Task / Requests / Mentioned
CompleteOwn AccountAssignedNoneNoneOwn AccountNone
Export Request ReportOwn AccountAssignedOwn AccountNoneOwn AccountAssigned
Notified upon new RequestAssignedAssignedNoneNoneAssignedAssigned
Extend the requestOwn AccountAssignedNoneNoneOwn AccountAssigned
Change AssigneeOwn AccountAssignedNoneNoneOwn AccountAssigned
Download Intake Form Attachment/sOwn AccountAssignedNoneNoneOwn AccountAssigned
Comments in the RequestViewOwn AccountAssigned to Task / Requests / MentionedOwn AccountAssigned to Task / MentionedOwn AccountAssigned to Task / Requests / Mentioned
PostOwn AccountAssigned to Task / Requests / MentionedOwn AccountAssigned to Task / MentionedOwn AccountAssigned to Task / Requests / Mentioned
UpdateOwnOwnNoneOwnOwnOwn
DeleteOwn AccountOwnNoneOwnOwn AccountOwn
Attachments in the RequestViewOwn AccountAssignedOwn AccountOwn Account MentionedOwn AccountAssigned
UploadOwn AccountAssignedNoneOwn Account MentionedOwn Account Assigned
DownloadOwn AccountAssignedNoneOwnOwn Account Assigned
DeleteOwn AccountAssignedNoneOwnOwn AccountAssigned
Assignee ConfigurationViewOwn AccountNoneNoneNoneNoneNone
Add Conditional AssigneeOwn AccountNoneNoneNoneNoneNone
Update Conditional AssigneeOwn AccountNoneNoneNoneNoneNone
Delete Conditional AssigneeOwn AccountNoneNoneNoneNoneNone
Add Default AssigneeOwn AccountNoneNoneNoneNoneNone
Delete Default AssigneeOwn AccountNoneNoneNoneNoneNone
Translation LibraryView TranslationsOwn AccountNoneNoneNoneNoneNone
Add TranslationOwn AccountNoneNoneNoneNoneNone
Update TranslationOwn AccountNoneNoneNoneNoneNone
Delete TranslationOwn AccountNoneNoneNoneNoneNone
Intake Forms ConfigurationView Intake FormsOwn AccountNoneNoneNoneNoneNone
Create Intake FormsOwn AccountNoneNoneNoneNoneNone
Update Intake FormsOwn AccountNoneNoneNoneNoneNone
Delete Intake FormsOwn AccountNoneNoneNoneNoneNone
Email Templates / Landing Pages / Task Templates SettingViewOwn AccountNoneNoneNoneNoneNone
CreateOwn AccountNoneNoneNoneNone 
UpdateOwn AccountNoneNoneNoneNoneNone
DeleteOwn AccountNoneNoneNoneNoneNone
Tasks under RequestsView TasksAssigned to Task / Requests / Mentioned in the TasksAssigned to Task / Requests / Mentioned in the TasksOwn Account

Assigned to

Task / Mentioned in the Tasks

Own AccountAssigned to Task / Requests / Mentioned in the Tasks
Create tasks manuallyOwn AccountAssigned to RequestsNoneNoneOwn AccountAssigned to Requests
Update tasksOwn Account

Assigned to Task /

Requests

NoneAssigned to TaskOwn AccountAssigned to Task / Requests
Update subtasksOwn AccountAssigned to Task / RequestsNoneAssigned to Subtask/TaskOwn AccountAssigned to Task / Requests
Delete tasksOwn AccountAssigned to RequestsNoneNoneOwn AccountAssigned to Requests
Create subtasks manuallyOwn AccountAssigned to Task / RequestsNoneAssigned to Subtask / TaskOwn AccountAssigned to Task / Requests
Attachments in TasksViewOwn AccountAssigned to Task / Requests / MentionedOwn AccountAssigned to Task / Mentioned in the TaskOwn AccountAssigned to Task / Requests / Mentioned
UploadOwn AccountAssigned to Task / Requests / MentionedOwn AccountAssigned to Task / Mentioned in the TaskOwn AccountAssigned to Task / Requests / Mentioned
DownloadOwn AccountAssigned to Task / RequestsOwn AccountAssigned to TaskOwn AccountAssigned to Task / Requests
DeleteOwn AccountOwnNoneOwnOwn AccountOwn
Comments in TasksViewOwn AccountAssigned to Tasks / Requests / MentionedOwn AccountAssigned to Task / Mentioned in the TaskOwn AccountAssigned to Task / Requests / Mentioned
PostOwn AccountAssigned to Tasks / Requests / MentionedOwn AccountAssigned to Task / Mentioned in the TaskOwn AccountAssigned to Task / Requests / Mentioned
UpdateOwn AccountOwnNoneOwnOwn AccountOwn
DeleteOwn AccountOwnNoneOwnOwn AccountOwn