Roles & Permissions
The five roles, what each can do, and how visibility scope works separately from role.
The five roles
Reviewer
Reviews and redacts the documents assigned to them. A Reviewer decides each detection — “Redact” or “Don’t redact — keep visible” — assigns withholding grounds, and presses “Sign Off” when a document is done. Reviewers can generate the “Requester Package” but cannot send work back or give final sign-off.
Senior Reviewer
Reviews decisions, can request changes, and makes disclosure decisions. A Senior Reviewer can “Request Changes” → “Send Back” to return a document to “In Review”, and can generate the “Internal Package” — but does not give final sign-off.
Final Approver
Reviews, redacts, and gives the final sign-off. “Final Approval” freezes a document as “Signed Off”; an assigned Final Approver (or an assigned Lead) then completes the case-level “Final sign-off” and presses “Attest case complete”. Final Approvers have org-wide visibility and can generate any package, including the “Ombudsman Package”.
The Lead
The request manager. The Lead creates cases with “Log a new request”, assigns work, sets deadlines, and configures the workflow — and can also review and sign off. Only the Lead can extend a deadline, delete a document, press “Mark as released”, and “Close & archive” a case. The Lead also manages “Custom Rules” and has org-wide visibility.
Administrator
System configuration only — users, integrations, and detection settings. Custom detection rules belong to the Lead and the Senior Reviewer. The Administrator has no access to cases: they cannot see cases, review documents, generate any package, or use the “Reports” screen.
Who can do what
| Capability | Reviewer | Senior Reviewer | Final Approver | Lead | Administrator |
|---|---|---|---|---|---|
| Review & decide detections, assign grounds * | ✓ | ✓ | ✓ | ✓ | — |
| Request changes / send back | — | ✓ | ✓ | ✓ | — |
| Final sign-off on a document | — | — | ✓ | ✓ | — |
| Create a case, extend a deadline, release, close, delete a document | — | — | — | ✓ | — |
| Generate “Requester Package” | ✓ | ✓ | ✓ | ✓ | — |
| Generate “Internal Package” | — | ✓ | ✓ | ✓ | — |
| Generate “Ombudsman Package” | — | — | ✓ | ✓ | — |
| Manage “Custom Rules” | — | ✓ | — | ✓ | — |
| “Reports” access | ✓ | ✓ | ✓ | ✓ | — |
* Reviewing detections and assigning grounds requires being an assigned participant on the case — role alone is not enough. Likewise, the case-level attestation is completed by an assigned Final Approver (or an assigned Lead); the Lead then releases or closes.
Visibility scope — separate from role
What you can see is set by scope, separately from what your role can do:
- Department scope — you see only cases that include your department.
- Org-wide scope — you see every case. The Lead and the Final Approver are org-wide.
- Within a shared multi-department case, documents are further scoped to the department that owns them.
- The Administrator has no case access at all, whatever the scope.
Two people with the same role can therefore see different cases — a department-scoped Senior Reviewer works only their department’s requests, while an org-wide one sees everything.