Odau

Roles & Permissions

What each role may do — 28 permissions across six categories. A change here takes effect on the next page load for anybody acting as that role.

Roles

Roles

Full operational access, plus configuration.

28 of 28
Applications & Records
Application records
Manual application submission
Create a record by hand, without a procurement request.
Deactivate applications
Resolve non-managed applications
Claim a discovered application and complete its record.
Reassign ownership
Procurement & Contracts
Procurement requests
Who approves is set on the workflow itself, not here.
Contract records
Purchase records
Convert a purchase to a contract
Access Controls
Access controls
Onboard and deprovision users
Managers can already do this for their own direct reports; this grants it beyond that scope.
Revoke access
Revocation happens in the tool; Odau records the outcome.
Dashboards & Reports
Spend and financial data
Portfolio performance
Usage signals
Operational health
Financial insights
Create reports
Share reports
Waste report
Governance & Security
Security governance
Audit trail and evidence
Evidence export package
Settings
Platform settings
Connect and disconnect integrations
Account and billing
Notification configuration
Role management
Create roles and change what any role can do.
Saving changes what anybody viewing as this role can reach, on their next page load.

What These Levels Mean

View shows a surface without allowing changes. Edit allows changes to it. Allow is for discrete actions that are either permitted or not, with no middle state.

Each permission offers only the levels it defines, so a view-only permission never shows Edit. Where a role has no permission recorded, it reads as None.

Approving requests is deliberately not a permission. Approvers are named on the approval workflow itself in Settings → Configuration, so that who approves what has one source rather than two.