Roles, permissions and reviewer accounts: how we let clients in safely
Giving a client, a contractor or an auditor access to a twin should never mean giving them access to everything else on the platform. Here is how we draw that line.
A platform that holds compliance evidence, claims data and site security information for multiple clients has to get access control right, not as an afterthought, but as a foundation. Getting it wrong in either direction is a real problem, too restrictive and the platform is not useful day to day, too loose and it is not trustworthy.
Twenty roles, not one generic login
The platform defines twenty distinct roles across internal and client tenants, mapped against a permission matrix covering more than thirty individual features, built on standard role based access control principles. An Admin has full platform and tenant management access. A Manager has project or site oversight and reporting. An Operator can capture and do basic annotation. A Viewer has read only access to whatever has been shared with them, nothing more.
Why the Reviewer role specifically matters
Between Manager and Viewer sits a role we use constantly: Reviewer, which allows viewing, annotating and formally approving findings, without granting the broader management access a Manager account carries. That is the role a client, an external auditor or an insurer's own surveyor typically gets, enough access to genuinely engage with the evidence, without exposing the rest of the tenant's data.
Why we did not simplify this to three roles: a smaller role set is easier to build and explain. It is also less honest about how differently an Admin, a Site Manager and an external auditor actually need to use the same underlying twin. Twenty roles is more engineering than three, and it is the right amount for the range of people who genuinely need access.
This access model sits underneath every feature covered elsewhere in this series, from reports and review workflows to reviewer only client accounts. See our product page for the full feature set.
See the permission model in detail
If your procurement process needs a detailed breakdown of our role and permission model, we can walk your security or IT team through it directly.
Talk to us