Roles & Permissions

The five roles, what each can do, and how visibility scope works separately from role.

The five roles

Reviewer

Reviews and redacts the documents assigned to them. A Reviewer decides each detection — “Redact” or “Don’t redact — keep visible” — assigns withholding grounds, and presses “Sign Off” when a document is done. Reviewers can generate the “Requester Package” but cannot send work back or give final sign-off.

Senior Reviewer

Reviews decisions, can request changes, and makes disclosure decisions. A Senior Reviewer can “Request Changes”“Send Back” to return a document to “In Review”, and can generate the “Internal Package” — but does not give final sign-off.

Final Approver

Reviews, redacts, and gives the final sign-off. “Final Approval” freezes a document as “Signed Off”; an assigned Final Approver (or an assigned Lead) then completes the case-level “Final sign-off” and presses “Attest case complete”. Final Approvers have org-wide visibility and can generate any package, including the “Ombudsman Package”.

The Lead

The request manager. The Lead creates cases with “Log a new request”, assigns work, sets deadlines, and configures the workflow — and can also review and sign off. Only the Lead can extend a deadline, delete a document, press “Mark as released”, and “Close & archive” a case. The Lead also manages “Custom Rules” and has org-wide visibility.

Under LGOIMA the request manager is shown as “LGOIMA Lead”. Under OIA the request manager is shown as “OIA Lead”.

Administrator

System configuration only — users, integrations, and detection settings. Custom detection rules belong to the Lead and the Senior Reviewer. The Administrator has no access to cases: they cannot see cases, review documents, generate any package, or use the “Reports” screen.

⚠ Warning: The Administrator has no case access. If someone needs to both configure the system and work cases, they need a case role — Administrator alone is never enough.

Who can do what

Capability Reviewer Senior Reviewer Final Approver Lead Administrator
Review & decide detections, assign grounds *
Request changes / send back
Final sign-off on a document
Create a case, extend a deadline, release, close, delete a document
Generate “Requester Package”
Generate “Internal Package”
Generate “Ombudsman Package”
Manage “Custom Rules”
“Reports” access

* Reviewing detections and assigning grounds requires being an assigned participant on the case — role alone is not enough. Likewise, the case-level attestation is completed by an assigned Final Approver (or an assigned Lead); the Lead then releases or closes.

Tip: Permissions are enforced by the server, not the screen. Some buttons you cannot use are hidden; others are visible but will be rejected by the server — never assume access from the UI alone. The system re-checks your role on every action.

Visibility scope — separate from role

What you can see is set by scope, separately from what your role can do:

Two people with the same role can therefore see different cases — a department-scoped Senior Reviewer works only their department’s requests, while an org-wide one sees everything.

← Solution Overview Feature Reference →