Skip to content
ClearGRC User Guide

ClearGRC User Guide

  • Documentation
ClearGRC User Guide
ClearGRC User Guide

Getting Started

3
  • Navigation
  • Understanding the Dashboard
  • Signing In

Governance

6
  • Exception
  • Process
  • Company Setup
  • Third-Party Inventory
  • Document Inventory
  • Policy Center

Risk

5
  • Threats
  • Assets
  • Vulnerabilities
  • Controls
  • Risk Register

Compliance

3
  • Audit Inventory
  • Cross Reference
  • Assessments

Administration

5
  • Roles and Permissions
  • Reports
  • Application Settings
  • Notifications
  • Users and Roles

FAQ

1
  • Frequently Asked Questions

Troubleshooting

1
  • Troubleshooting
View Categories
  • Home
  • Docs
  • Administration
  • Roles and Permissions

Roles and Permissions

2 min read

ClearGRC uses role-based access control (RBAC) to determine which modules a user can access and which actions they can perform. Each role grants a combination of seven permission types across modules:

Permission What it allows
Read View records
Execute Run operations (e.g. submit, trigger)
Add Create new records
Edit Modify existing records
Delete Remove records
Review Submit a review decision
Approve Grant final approval

Built-In Roles #

ClearGRC includes the following built-in roles. A user’s effective permissions are the union of all roles assigned to them.

Role Description Typical Assignment
Admin Full access (Read, Execute, Add, Edit, Delete, Review, Approve) across all GRC modules. System administrators
Owner Full access to modules for records the user owns, including create, read, edit, delete, review, and approve. Policy owners, control owners, risk owners
Approver Read and approve access across modules. Cannot create, edit, or delete records. Compliance managers, risk managers acting as final sign-off
Reviewer Read and review access across modules. Cannot modify, delete, or approve records. Internal reviewers, subject matter experts
Custodian Read, add, and edit access across modules. Cannot review or approve records. Data or asset custodians
User Read-only access across modules. General department or business users
TPUser Read, execute, add, and edit access limited to the Assessment module. Cannot delete or approve. External vendors and third parties responding to assessments

Additional specialized roles – such as Auditor, Data Owner, Information Security Manager, and Privacy roles – may also be available depending on your organization’s ClearGRC configuration.

Assigning Roles #

Administrators assign roles to users from Admin → Users. When creating or editing a user record, one or more roles can be applied. A user’s effective permissions are the combined union of all assigned roles.

[Screenshot: User record showing role assignment]

Viewing Your Own Permissions #

Any signed-in user can inspect their own effective permissions from My Profile → Permissions. This screen displays a matrix of every module against the seven permission types, grouped by each assigned role, with green checkmarks indicating granted permissions. A search bar and column filter allow you to narrow the matrix to specific modules.

[Screenshot: My Profile → Permissions matrix]

Note: Administrators can view the permission matrix for any role in the tenant from Admin → Permission Inventory.

Updated on July 23, 2026

What are your Feelings

  • Happy
  • Normal
  • Sad

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Users and RolesReports
Table of Contents
  • Built-In Roles
  • Assigning Roles
  • Viewing Your Own Permissions

© 2026 ClearGRC User Guide

  • Documentation