Start here
Roles and responsibilities
Learn what administrators, preparers, reviewers, and read-only users can do.
Who should read this
Administrators who grant access and every user who participates in a filing.
Before you begin
Roles are assigned per organization. A separate table-level allowlist may narrow a member’s edit or review scope. A role never grants access to another organization.
Responsibilities
- Administrator: configures the organization, reporting entities, authority profiles, users, access, and filing cycles. Administrators can also perform preparation and review tasks.
- Preparer: imports or enters values, resolves findings, manages supporting evidence, and submits a filing for review.
- Reviewer: reviews an assigned filing, comments, requests changes, and approves and locks it when their review scope covers the filing.
- Read-only user: can inspect permitted filing information but cannot change the filing.
Separation of duties
Where your policy requires independent review, use different preparer and reviewer accounts. Administrator capability does not replace your organization’s approval policy.
Expected result
Each person has the least access needed for their task, and the assigned reviewer can review all required tables.
How to verify
An administrator opens Review and audit, checks the member list and table access, then asks each user to confirm that expected controls are visible and restricted controls are unavailable.
Common problems
- A reviewer cannot approve when they are not the assigned reviewer.
- A reviewer cannot approve when their review allowlist omits a selected table.
- A pending invitation must be accepted with the exact invited account email before organization access is granted.
Audit and data consequences
Actions are attributed to the signed-in account. Do not share accounts. Changing a role affects future access; it does not rewrite earlier audit attribution. Removing a membership ends that account's access to the organization without deleting its earlier attributed audit activity.
Product limitations
The current email/password profile provides email invitations and password reset through configured SMTP. It does not provide single sign-on or a self-service active-session dashboard. A successful password reset revokes the account's existing sessions.