More user permissions on Secfix
As Secfix grows, I see the need to allow companies to better segment their user permissions (not only between admin or employee).
As Secfix grows, I see the need to allow companies to better segment their user permissions (not only between admin or employee).
Log in to comment and vote
Comments9
Oct 22, 2025
User permissions are now live!
We’ve added three new roles:
Editor: Edit all content except sensitive pages.
Collaborator: Edit only items assigned to them.
View-only Admin: Full visibility, no editing.
Jun 23, 2025
🚀 We have an update for you!
We're excited to share that we've started working on two new roles for Secfix: Editor and Collaborator.
Editor: Can view and edit all content except sensitive pages (like Employees, Access, and Computers).
Collaborator: Can be assigned as owners of items like policies, risk scenarios, vendors, inventory, manual evidence, and checks. They can view and edit only the items assigned to them.
We're currently building an MVP version, so this is just the beginning. More updates to come 😊
Jun 13, 2025
Jan Wagner
May 30, 2025
This is a great idea and in addition with role based access where you can assign tasks, risks and so on to a role instead of users, that will scale well and reduces operational overhead if employees or responsibilities changing.
Jakub Wanat
Apr 3, 2025
Marc Morone would like to define and limit what auditors can see within their Secfix instance (e.g., certain risks, modules like employees or access, or outdated inventory items like old employee laptops). Current access model only allows full access or no access, with no granularity to hide or expose specific sections. A more flexible access control (e.g., by module or asset type) would help limit exposure of work-in-progress or irrelevant data during audits.
Sophia Fries
Nov 26, 2024
Another client requested this feature, it would be great if was possible to select different permissions for the Admin role, so not all admins can see all features on Secfix. Example, Head of IT team will need to complete the IT risk assessment but they should not have access to edit Vendors or Policies on the platform.
Ghada Shebl
Jul 9, 2024
Alper Thank you for your feedback! To prioritize, which roles or permissions do you believe are crucial to include, aside from admin and employee?
Bettina Niklaus
Jul 10, 2024
Ghada Shebl In our Use Case, we would need the ISMS Council / Team with a special role, they are e.g. Risk Owners and should be able to see the risks and also approve them and work on tasks assigned to risks, but they don't work on Policies, Manual Evidences, etc. Maybe the role could also be more generic for the usage, e.g. "Risk Managers".
Florian H.
Jul 10, 2024
Ghada Shebl from our perspective:
admin
management: access to some features like Risk register but not full admin
normal employee
external employee