User roles and permissions

Understand what each role can do, and change a user's role in your workspace

Written By Micah

Roles control what each person in your workspace can see and change. Assigning them deliberately keeps your compliance program tidy: the people responsible for a risk, control, or evidence item can maintain it, your audit partner can review without altering anything, and administrative control stays with the people who should have it. It also gives you a clean answer when an auditor asks how you restrict access to your compliance system.

Where to find user roles and permissions

Go to Team Settings (gear icon in lower left), then open the Users & Permissions tab.

The tab lists everyone in your workspace with their username, the date they joined, and their current role.

If you do not see the Users & Permissions tab, one of two things is true: you are not a Manager, or the feature is not enabled for your organization. Only Managers can view and change roles. Reach out to support or your Customer Success Manager if you need access.

Compliance roles

These are the roles for people working in your compliance program.

Manager

Contributor

Auditor

View risks, controls, evidence, and criteria

Yes

Yes

Yes

Edit risks, controls, and evidence

All items

Items they own

No

Comment on items

Yes

Yes

Yes

Attach and collect evidence

Yes

Items they own

No

Configure Integrations

Yes

Yes

No

Manage Verify AI test results

Yes

Items they own

No

Work with security questionnaires

Yes

Yes

No

Use the Security Assistant MCP server

Yes

Yes

No

Invite users and change roles

Yes

No

No

Deactivate users

Yes

No

No

A Contributor who does not own an item has read-only access to it. Ownership is what grants edit rights, so reassigning an owner also moves the ability to maintain that item.

The Auditor role is read-only across your compliance data, with commenting as the one exception. That combination is what makes it appropriate for an external audit partner: they can review your program and raise questions in-product without changing your records.

Trust roles

These roles are for people who work in your Trust Center, Trust Asset Library, and Trust Chain rather than your compliance program.

Trust roles replace compliance access rather than adding to it. A user with a trust role cannot reach risks, controls, evidence, or criteria at all.

Trust Manager

Trust Contributor

Trust Viewer

View the Trust Asset Library and Action Items

Yes

Yes

Yes

Answer and edit security questionnaires

Yes

Yes

No

Delete security questionnaires

Any questionnaire

Only ones they submitted

No

Use the Security Assistant MCP server

Yes

Yes

No

View Trust Center access requests

Yes

Yes

No

Approve Trust Center access requests

Yes

Only when assigned

No

View your organization's own security posture, including findings withheld from customers

Yes

No

No

Access risks, controls, evidence, and criteria

No

No

No

Managers keep access to Trust Center surfaces alongside their compliance access, so you do not need a second account to administer your Trust Center.

Change a user's role

  1. Go to Settings, then the Users & Permissions tab.

  2. Find the user in the table. You can sort by USERNAME or DATE JOINED, and page through the list if your workspace is large.

  3. Open the dropdown in the ROLE column for that user.

  4. Select the new role.

The change saves as soon as you select it, and you will see a "Role updated" confirmation. There is no separate save step. If the update fails, the dropdown returns to the previous role and an error message explains why.

Each user holds one role at a time. Selecting a new role replaces the old one.

Assign a role when inviting someone

You can set a role at the point of invitation instead of correcting it afterward:

  1. Click Invite Users on the Users & Permissions tab.

  2. Enter the email address.

  3. Choose the Role for the new user.

  4. Click Send Invite.

Pending invitations appear in the modal, and you can revoke one by selecting the invited user from the dropdown.

Note: a person who has a pending invitation to another organization must accept that invitation and finish signing up before they can be invited to an additional organization.

Download your user list

Click Download CSV on the Users & Permissions tab to export the current list of users and their roles.

This export is useful for periodic access reviews. Several frameworks expect evidence that you review who has access to your systems and at what privilege level, and this file covers that requirement for Strike Graph itself.

Deactivate a user

When someone leaves your organization or no longer needs access, use the menu at the end of their row in the table and select Deactivate.

Deactivating a user prompts you to reassign what they own, which prevents risks, controls, and evidence from being left without an owner. It also removes any user-specific integrations they configured and blocks their access to the product. Evidence attachments they uploaded are not deleted.

You cannot deactivate your own account from this table.

Which roles you will see

The roles available in the dropdown depend on what is enabled for your organization:

  • Contributor and Manager are always available.

  • Auditor appears when the Auditor role is enabled for your organization.

  • Trust Viewer, Trust Contributor, and Trust Manager appear when your organization has the Trust Asset Library, Trust Center, or Trust Chain enabled.

If a role you expect is missing, contact support or your Customer Success Manager to confirm whether it is available on your plan.

Questions?

Reach out through our chat feature for real-time Customer Success support 8 AM–5 PM PT Monday through Friday.