ReFresh assigns each user a role (Organization Admin, Compliance Manager, or Member) that controls what they can see and do, with group membership layering further access on top.
Three roles available when inviting users: Organization Admin, Compliance Manager, Member
Roles are set at invite time at Settings → Invites
Group membership controls data access at the team, department, or site level
Granular permissions sit behind each role and are managed by ReFresh
Platform Admin is reserved for ReFresh staff and cannot be granted by customers
The roles you can assign
When you invite a user (Settings → Invites → Invite Users), you choose their role from three options:
Organization Admin: full access to your organisation, including settings, billing, framework activation, all compliance modules, and user management
Compliance Manager: admin access scoped to compliance work (risks, controls, evidence, incidents, surveys, reports), without billing or user management
Member: worker-level access through My ReFresh, used for incident reporting, completing surveys, and acknowledging documentation
The role you choose at invite time is applied when the user accepts the invitation.
Group-level access
Groups (teams, departments, business units) provide a second layer of access control. A user assigned to a group can see and act on data scoped to that group.
For more detail on how groups work and how membership controls reporting and data visibility, see "Creating and managing groups" (2.2).
Granular permissions
Each role is built from granular permissions that map to specific actions on specific resources. ReFresh manages the underlying permission model. Customers do not configure individual permissions directly: they assign one of the three available roles and the relevant group memberships.
If you have a specific access requirement that the standard roles do not cover, contact your ReFresh account contact.
Platform Admin
Platform Admin is a ReFresh-staff-only role used for tenant oversight, compliance library management, and platform configuration. It cannot be granted by customer admins. The highest customer-grantable role is Organization Admin.
Related articles
Adding and managing users (2.3)
Creating and managing groups (2.2)
Setting up SSO (2.6)
Multi-factor authentication (2.7)