Docs menu
Roles & Access Administration

Simple default roles, with a fully custom model underneath.

Every workspace has a simple default (Viewer/Editor/Admin) and a fully custom model underneath it, for teams that need finer control.

The model

Three layers, from individual permission to person.

  • Access rights — individual, named permissions (e.g. the right to view an audit trail, or approve a transfer)
  • Access configurations — named bundles of access rights, functioning as custom roles
  • Assignment — a configuration is assigned to a specific person

Viewer, Editor, Admin covers most teams.

Most workspaces never need more than the three starting roles from Getting Started — Viewer, Editor, and Admin. They're simple defaults, not a ceiling.

Custom configurations for regulated, role-specific access.

For teams that need finer-grained control — a QA Auditor who can only export audit trails, a Custodian who can only approve custody transfers — custom access configurations give you that precision. See the Configuration Guide's role → access-rights mapping for the exact rights used in Sample Management.

What's in the admin console today

Available in the admin console today.

Available
  • Create and manage individual access rights
  • Bundle rights into named, reusable access configurations
  • Assign configurations to individual users
  • Every assignment and change captured in the audit trail