Skip to main content

User roles and permissions

Every user in ReFresh has a role that controls what they can see and do, and their group membership layers data access on top. Roles are set at invite time and can be changed later.

Written by Taylor Laing
  • Three roles: Member (the default), Admin, and Organization Admin

  • Roles are chosen when you invite a user (Settings → Invites) and applied when they accept

  • Group membership controls which data a user can see, at the team, department, or site level

  • Groups do not carry their own "admin" or "member" role; access comes from the person's platform role plus which groups they belong to

  • The permission model is managed by ReFresh; customers assign roles and groups rather than editing individual permissions

The three roles

ReFresh uses three roles, from most access to least:

  • Organization Admin: full administrative ownership of your organisation's ReFresh instance (tenant), including people, settings, subscription and billing, framework activation, and every compliance area.

  • Admin: administrative access across the compliance areas (risks, controls, records, incidents, surveys, reviews, reports). The default role assigned to new admin users.

  • Member: day-to-day worker access through My ReFresh: reporting incidents, completing assigned surveys, and acknowledging policies and documents. This is the baseline role everyone receives.

The role you choose at invite time takes effect when the user accepts the invitation. You can change a user's role afterwards from Settings → Employees.

Group-level access

Roles decide what kind of actions a user can take. Groups decide which data those actions apply to.

Groups represent teams, departments, business units, regions, sites, and other working units. A user assigned to a group can see and act on the data scoped to that group. Someone who manages a single department, for example, works within that department's risks, controls, and incidents rather than the whole organisation.

Importantly, a group does not give a person a separate "admin" or "member" role inside it. Access comes from the combination of the user's platform role and the groups they belong to. Some groups also carry specialised capabilities (for example, being the group that handles incident triage), but these are properties of the group, not extra roles for its members.

For how groups are created and structured, see Creating and managing groups.

How permissions work behind the roles

Each role is built from a fine-grained permission model that maps specific actions to specific resources. ReFresh maintains this model and enforces it consistently across the interface, the API, and the database itself, so a user can only ever see and do what their role and groups allow.

Customers do not build or edit individual permissions, and there is no custom-role builder; you assign one of the three built-in roles plus the relevant group memberships. If you have an access requirement the standard roles do not cover, contact your ReFresh account contact.

Did this answer your question?