> ## Documentation Index
> Fetch the complete documentation index at: https://iru-kbee-63-enhance-rts-documentation.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance Permissions

> Configure role-based access controls for Iru Compliance. Assign permissions to team members for frameworks, actions, evidence, and Trust Center.

### About Compliance Roles

Iru Compliance uses role-based access control. The [permissions overview](#permissions-overview) spells out what each role can open or change: search, actions, frameworks (controls and control-linked evidence), artifacts, sources, policies, Trust Center, and related areas. Behavior varies by role. In the tables, **Compliance Admin**, **Compliance Collaborator**, and **Compliance Auditor** sit next to **Admin**, **Standard**, and **Auditor** so you can compare Compliance-only assignments to the same permission pattern. Users with **Read activity logs** can review compliance and tenant activity on the [Unified Activity](/en/iru/platform-overview/unified-activity).

<Info>
  Need help with a step? [Contact Iru Support](/en/iru/iru-support/access-to-iru-support).
</Info>

### Access Levels

#### Admin

Full access to all compliance functionality, including framework management, settings configuration, and administrative controls.

#### Standard

Most of the same permissions as **Admin**, with limits on framework and settings management.

#### Help Desk

Operational access for day-to-day compliance work, including managing actions, artifacts, and evidence collection.

#### Secrets Auditor

Read-only access with the ability to generate automated artifacts and assess artifact relevance.

#### Auditor

Read-only access for audit and review. In the **Frameworks** matrix, **Auditor** does not have **View controls** (the control definitions in a framework) but does have **View control action** and **View control artifact**, so reviewers can still follow actions and evidence tied to controls without editing control definitions. See the matrix for the full list.

#### Iru Support

Read-only access to support customer issues and troubleshooting.

### Compliance-Only Roles

These roles apply **only** within Iru Compliance. The **Compliance Admin**, **Compliance Collaborator**, and **Compliance Auditor** columns match **Admin**, **Standard**, and **Auditor**; they do not grant access outside the Compliance area. For tenant-wide roles across Endpoint, Identity, and the rest of the platform, see [Team Member Role Permissions](/en/iru/access/team-member-role-permissions).

#### Compliance Admin

Administrator-level access in Iru Compliance only. Matches the **Admin** column in the [permissions overview](#permissions-overview). This is not tenant-wide **Administrator** access across products.

#### Compliance Collaborator

Matches the **Standard** column for team members whose access is limited to Iru Compliance.

#### Compliance Auditor

Matches the **Auditor** column for team members whose access is limited to Iru Compliance. Under **Frameworks**, **Compliance Auditor** behaves like **Auditor**: no **View controls**, with **View control action** and **View control artifact** for reviews.

#### Compliance Employee

Access limited to acknowledging company policies. This role has its own view in Compliance and does not include Iru AI access. See [Iru AI](#iru-ai).

### Permissions Overview

#### General

| Permission | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support |
| ---------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- |
| Search     | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |

#### Actions

| Permission                       | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support |
| -------------------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- |
| View list                        | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| View action details              | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Create                           | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Update                           | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |
| Delete                           | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |
| Upload artifact                  | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |
| Delete artifact                  | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |
| Generate automated artifact      | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ❌           |
| Generate automated artifact bulk | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ❌           |
| Assess artifact relevance        | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ❌           |
| Read comments                    | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Create comment                   | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ❌           |
| Update comment                   | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ❌           |
| Delete comment                   | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ❌           |
| Read activity logs               | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ❌           |

#### Frameworks

| Permission               | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support |
| ------------------------ | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- |
| List frameworks          | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| View framework details   | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| View framework readiness | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Add frameworks           | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Remove frameworks        | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| View controls            | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |
| Add controls             | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |
| Edit control             | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Remove controls          | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| View control action      | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Add control action       | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Edit control actions     | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |
| Remove control action    | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| View control artifact    | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Upload control artifact  | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |
| Remove control artifact  | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |

#### Artifacts

| Permission             | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support |
| ---------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- |
| View list of artifacts | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| View artifact details  | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Edit artifact details  | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |
| Upload artifact        | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |
| Replace file           | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |
| Remove artifact        | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |

#### Sources

| Permission           | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support |
| -------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- |
| View list of sources | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Connect source       | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |
| Disconnect source    | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ❌       | ❌                  | ❌           |

#### Policies

Use **Compliance → Policies** to create, publish, and track acknowledgements for security and compliance policies. See [Policies Management](/en/compliance/policies-management) for the library, template generation, editor, and workforce acknowledgement flows.

| Capability                          | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support |
| ----------------------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- |
| View published policies             | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Create and edit policies            | ✅     | ✅                | ✅        | ✅                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Publish and delete policies         | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Manage policy owners and categories | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| View acknowledgements (admin tab)   | ✅     | ✅                | ✅        | ✅                       | ❌         | ❌               | ✅       | ✅                  | ❌           |

**Standard** and **Compliance Collaborator** can create and edit draft policies but cannot publish or delete them, and cannot manage tenant-level policy settings such as owners and categories. **Auditor** and **Compliance Auditor** can view published policies and acknowledgement progress but cannot change policy content.

Workforce users are not Compliance administrators. When a policy is published, every user in the tenant sees assignments in **My Policies** and can acknowledge policies assigned to them. That portal is separate from the Compliance **Policies** admin view.

#### Trust Center: Editor

| Permission                  | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support |
| --------------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- |
| Read settings               | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Create settings             | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Update settings             | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Upload logo                 | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Remove logo                 | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Upload NDA                  | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Remove NDA                  | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Read certifications         | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Upload certification icon   | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Delete custom certification | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |

#### Trust Center: Answers

| Permission              | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support |
| ----------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- |
| Read answers            | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Update answers          | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Delete answers          | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Read answers category   | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Create answers category | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Update answers category | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Delete answers category | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |

#### Trust Center: Artifacts

| Permission               | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support |
| ------------------------ | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- |
| Read document category   | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Update document category | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Delete document category | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |

#### Trust Center: Accounts

| Permission                  | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support |
| --------------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- |
| Read accounts               | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Read pending accounts       | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Get signed NDA download URL | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Approve account             | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Delete account              | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |

#### Trust Center: Questionnaires

| Permission                 | Admin | Compliance Admin | Standard | Compliance Collaborator | Help Desk | Secrets Auditor | Auditor | Compliance Auditor | Iru Support |
| -------------------------- | ----- | ---------------- | -------- | ----------------------- | --------- | --------------- | ------- | ------------------ | ----------- |
| Read questionnaire list    | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Read questionnaire details | ✅     | ✅                | ✅        | ✅                       | ✅         | ✅               | ✅       | ✅                  | ✅           |
| Update questionnaire       | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Add questionnaire          | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |
| Delete questionnaire       | ✅     | ✅                | ❌        | ❌                       | ❌         | ❌               | ❌       | ❌                  | ❌           |

#### Iru AI

Compliance-only roles reach the Compliance and Trust Center agents only. They do not have endpoint, vulnerability, or EDR entitlement, so Iru AI does not answer questions about the device fleet for these roles. For tenant-wide roles (Owner, Admin, Standard, and others), see [Team Member Role Permissions](/en/iru/access/team-member-role-permissions).

| Permission                                | Compliance Admin | Compliance Collaborator | Compliance Auditor | Compliance Employee |
| ----------------------------------------- | ---------------- | ----------------------- | ------------------ | ------------------- |
| Access Iru AI                             | ✅                | ✅                       | ✅                  | ❌                   |
| Documentation & Support Q\&A              | ✅                | ✅                       | ✅                  | ❌                   |
| Compliance Agent                          | ✅                | ✅                       | Limited            | ❌                   |
| Trust Center Agent                        | ✅                | ✅                       | ✅                  | ❌                   |
| Endpoint Management / Vulnerability / EDR | ❌                | ❌                       | ❌                  | ❌                   |
| Recommendations                           | ❌                | ❌                       | ❌                  | ❌                   |
| Execute Iru AI Actions                    | ❌                | ❌                       | ❌                  | ❌                   |
| Audit event history                       | ❌                | ❌                       | ❌                  | ❌                   |

**Limited (Compliance Auditor):** The Compliance agent runs, but control definitions are withheld. Linked actions and artifacts are still available. This matches **Auditor** and **Compliance Auditor** under **Frameworks** (**View controls** is off).

**Compliance Admin** and **Compliance Collaborator** receive full Compliance and Trust Center answers, including control definitions. Audit event history is not available through Iru AI to any compliance role. For how agents work and how to enable Iru AI for the organization, see [Iru AI Overview](/en/iru/iru-ai/iru-ai-overview).

### Common Permission Issues

Use this section when a control is missing or a button has no effect.

<AccordionGroup>
  <Accordion title="Cannot add or remove a framework">
    Only **Admin** or **Compliance Admin** can add or remove frameworks. **Standard**, **Compliance Collaborator**, and **Help Desk** cannot.
  </Accordion>

  <Accordion title="Cannot open control definitions as Auditor">
    The **Frameworks** matrix sets **View controls** to off for **Auditor** and **Compliance Auditor**, while **View control action** and **View control artifact** stay on so reviewers can follow actions and evidence without editing control definitions. This is expected.
  </Accordion>

  <Accordion title="Cannot edit a control’s definition">
    Only **Admin** or **Compliance Admin** can edit existing controls. Other roles may add controls or edit control actions only where the **Frameworks** matrix allows.
  </Accordion>

  <Accordion title="Cannot approve control update recommendations">
    Iru AI **Control Update** recommendations (from **Home** → **Insights**, **Frameworks**, or a framework detail page) require permission to approve or reject proposed control and action text. View-only roles may see that a recommendation exists but cannot act on it. See [Adaptive Compliance](/en/compliance/adaptive-compliance) for the review workflow and who can approve changes in your tenant.
  </Accordion>

  <Accordion title="Cannot connect or disconnect a source">
    **Auditor**, **Compliance Auditor**, and **Iru Support** cannot manage sources. Use **Admin**, **Compliance Admin**, **Standard**, **Compliance Collaborator**, or **Help Desk** as listed under **Sources**.
  </Accordion>

  <Accordion title="Cannot upload artifacts on an action">
    **Auditor** and **Compliance Auditor** are read-only for uploads. Use **Admin**, **Compliance Admin**, **Standard**, **Compliance Collaborator**, **Help Desk**, or **Secrets Auditor** as allowed in the **Actions** table.
  </Accordion>

  <Accordion title="Cannot publish or delete a policy">
    Only **Admin** or **Compliance Admin** can publish or delete policies and manage policy owners and categories. **Standard** and **Compliance Collaborator** can create and edit drafts. See the **Policies** table and [Policies Management](/en/compliance/policies-management).
  </Accordion>

  <Accordion title="Cannot change Trust Center branding, Answers, or questionnaires">
    Trust Center **Editor**, **Answers**, and **Questionnaires** changes are **Admin** or **Compliance Admin** only unless the matrix shows otherwise.
  </Accordion>
</AccordionGroup>

If controls or actions look wrong for your access level, open the **Access** page to confirm your role ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**).

## Related Articles

<CardGroup cols={2}>
  <Card title="Getting Started With Compliance" icon="rocket" href="/en/compliance/getting-started-with-compliance">
    Core concepts and what you can do in Compliance.
  </Card>

  <Card title="Policies Management" icon="file-lines" href="/en/compliance/policies-management">
    Policy library, publishing, and acknowledgements.
  </Card>

  <Card title="Frameworks Management" icon="layer-group" href="/en/compliance/frameworks-management">
    Who can add or change frameworks by role.
  </Card>

  <Card title="Adaptive Compliance" icon="sparkles" href="/en/compliance/adaptive-compliance">
    Approving or rejecting Iru AI control and action updates.
  </Card>

  <Card title="Trust Center Management" icon="globe" href="/en/compliance/trust-center/trust-center-management">
    External sharing and Trust Center permissions.
  </Card>

  <Card title="Iru AI Overview" icon="sparkles" href="/en/iru/iru-ai/iru-ai-overview">
    How Iru AI agents work and how to enable Iru AI for the organization.
  </Card>

  <Card title="Team Member Role Permissions" icon="users" href="/en/iru/access/team-member-role-permissions">
    Tenant-wide roles in Iru (alongside the Compliance roles on this page).
  </Card>
</CardGroup>
