More granular user roles (e.g., Evidence Contributor, Risk Owner)
G
Gorka A.
It would be great to see more flexibility in how user roles are managed in the Secfix platform. Right now, there are only two options â Admin and Employee â which creates friction when trying to delegate responsibilities across the ISMS without giving full access.
For example, I want to assign HR-related evidence tasks to our HR lead, but they can't upload or manage evidence unless we promote them to Admin. This doesnât scale well and poses unnecessary access risks. A few role types weâd love to see:
- Evidence Contributor: Can upload and manage assigned evidences
- Risk Owner: Can view and manage risks they are assigned to
- Auditor (View-only): Read-only access for external or internal stakeholders
- Vendor / Contract Owner
- Human Resources Compliance
- Inventory Management
More granular roles would help us distribute ownership more efficiently and keep responsibility aligned with actual roles within our organization â without compromising security or overwhelming users with unnecessary access.
Created by Max Vogt