Roles & Permissions
What each role may do — 28 permissions across six categories. A change here takes effect on the next page load for anybody acting as that role.
Roles
Roles
Full operational access, plus configuration.
Applications & Records
Application records
Manual application submission
Deactivate applications
Resolve non-managed applications
Reassign ownership
Procurement & Contracts
Procurement requests
Contract records
Purchase records
Convert a purchase to a contract
Access Controls
Access controls
Onboard and deprovision users
Revoke access
Dashboards & Reports
Spend and financial data
Portfolio performance
Usage signals
Operational health
Financial insights
Create reports
Share reports
Waste report
Governance & Security
Security governance
Audit trail and evidence
Evidence export package
Settings
Platform settings
Connect and disconnect integrations
Account and billing
Notification configuration
Role management
What These Levels Mean
View shows a surface without allowing changes. Edit allows changes to it. Allow is for discrete actions that are either permitted or not, with no middle state.
Each permission offers only the levels it defines, so a view-only permission never shows Edit. Where a role has no permission recorded, it reads as None.