Who can do what in UprootSecurity?
UprootSecurity has five roles. Owners and Administrators run your compliance program. Members can see all of it without changing anything. Auditors get a scoped account for the audit they're assigned to. Portal Users are your employees, and they get My Uproot.
Give each person the smallest role that lets them do their job. That's least privilege, and how you apply it in your own tooling is one of the things an auditor will ask you about.
The five roles
Role | What it's for | What they can do |
|---|---|---|
Owner | The account your organization was created under | Everything, in every module |
Administrator | Whoever runs compliance day to day | Everything, in every module |
Member | Anyone who needs visibility — engineers, leadership | Read every module, plus their own policies, training and device in My Uproot |
Auditor | Your external auditor | Read your evidence, and record verdicts and comments inside the audit they're assigned to |
Portal User | Every employee | My Uproot — their policies, their training, their device, their own profile |
Everyone except a Portal User can see the whole console. What changes between the roles is what they can change.
One rule that surprises people: a Member can't be a assigned anything. Owning anything means acting on it, so the picker only offers roles that can act. If a colleague's name is missing from that list, their role is the reason — promote them and they'll appear.
Why everyone sees the whole menu
The sidebar shows the full program to everyone, deliberately. It isn't a list of your personal permissions — it's the map of what your organization is being held to. A Member who can see Controls, Tests, Policies and Audits knows what the company is being measured on, and that's the point of running compliance as a company-wide program rather than one admin's private console.
Two things follow from that:
- Access is checked on the page, not by hiding the link. A menu that draws fewer links isn't access control — hiding a link stops nobody. The check belongs where your data is, so that's where we do it, every time, for every role.
- A module your organization hasn't enabled is still on the menu. Opening it tells you it isn't switched on and points you to us. That's not a permission problem, and no role change opens it — it's a conversation about what you'd like your program to cover.
The tell, in one line: a missing button is a role question; "not enabled for your organization" is a coverage question.
Owner and Administrator
Both are full-access roles, and in daily work they do the same job: manage people and their roles, connect integrations, publish policies, run tests, and work across every module. Most organizations run with one Owner and a handful of Administrators.
The difference is accountability, not capability. The Owner is the account your organization was created under and the name your UprootSecurity contact works with. It's set when the organization is created, and it's the one role that can't be changed from People Access — so nobody can demote the Owner by accident. If it needs to move, because that person is leaving, ask your UprootSecurity contact.
What the Auditor role is for
Giving your auditor their own account is the point of running the audit in here. They sign in, read the controls, tests and evidence you've already assembled, record their verdicts, and raise comments you answer in the same place — instead of a mail thread and a shared folder.
The role is scoped to exactly that job:
- An Auditor records verdicts and comments inside an audit they've been assigned to. Creating, editing and completing the audit stays with your team.
- Only someone holding the Auditor role can be assigned to an audit.
Picking the right role
- Runs compliance day to day → Administrator.
- Needs to see the program but not change it → Member. Full visibility, nothing to break.
- Just needs to accept policies and finish training → Portal User. That's most of your company, and it's where everyone starts.
- External auditor → Auditor, and nothing else.
Promote people when they need to act, not in advance. Least privilege is much easier to hold than to retrofit.
Changing someone's role
Open People Access, open the person, and set their User Role. Owners and Administrators can do this; everyone else sees the role but can't change it.
If the person you're looking for isn't in People Access yet, they haven't arrived in UprootSecurity — see how people get into UprootSecurity.
Your role is one of two layers
Your role decides which modules you can open. The owner of an individual record decides who acts on that specific policy or vendor — which is why a policy can be waiting on one named person even when several people hold the same role. Owners and assignment covers that second layer.
