Skip to main content

More user permissions on Secfix

As Secfix grows, I see the need to allow companies to better segment their user permissions (not only between admin or employee).

Status: Complete9 comments

Log in to comment and vote

Comments9

  • Ghada Shebl changed status to Complete
    Team•

    Oct 22, 2025

    User permissions are now live!

    We’ve added three new roles:

    Editor: Edit all content except sensitive pages.

    Collaborator: Edit only items assigned to them.

    View-only Admin: Full visibility, no editing.

  • Ghada Shebl changed status to In Progress
    Team•

    Jun 23, 2025

    🚀 We have an update for you!

    We're excited to share that we've started working on two new roles for Secfix: Editor and Collaborator.

    Editor: Can view and edit all content except sensitive pages (like Employees, Access, and Computers).

    Collaborator: Can be assigned as owners of items like policies, risk scenarios, vendors, inventory, manual evidence, and checks. They can view and edit only the items assigned to them.

    We're currently building an MVP version, so this is just the beginning. More updates to come 😊

  • Ghada Shebl changed status to Under Review
    Team•

    Jun 13, 2025

  • Jan Wagner

    •

    May 30, 2025

    This is a great idea and in addition with role based access where you can assign tasks, risks and so on to a role instead of users, that will scale well and reduces operational overhead if employees or responsibilities changing.

  • Jakub Wanat

    Team•

    Apr 3, 2025

    Marc Morone would like to define and limit what auditors can see within their Secfix instance (e.g., certain risks, modules like employees or access, or outdated inventory items like old employee laptops). Current access model only allows full access or no access, with no granularity to hide or expose specific sections. A more flexible access control (e.g., by module or asset type) would help limit exposure of work-in-progress or irrelevant data during audits.

  • Sophia Fries

    •

    Nov 26, 2024

    Another client requested this feature, it would be great if was possible to select different permissions for the Admin role, so not all admins can see all features on Secfix. Example, Head of IT team will need to complete the IT risk assessment but they should not have access to edit Vendors or Policies on the platform.

  • Ghada Shebl

    Team•

    Jul 9, 2024

    Alper Thank you for your feedback! To prioritize, which roles or permissions do you believe are crucial to include, aside from admin and employee?

    • Bettina Niklaus

      •

      Jul 10, 2024

      Ghada Shebl In our Use Case, we would need the ISMS Council / Team with a special role, they are e.g. Risk Owners and should be able to see the risks and also approve them and work on tasks assigned to risks, but they don't work on Policies, Manual Evidences, etc. Maybe the role could also be more generic for the usage, e.g. "Risk Managers".

    • Florian H.

      •

      Jul 10, 2024

      Ghada Shebl from our perspective:

      • admin

      • management: access to some features like Risk register but not full admin

      • normal employee

      • external employee