Roles and permissions
How access works in Vendorica, why your roles belong to you, and how to change one without locking yourself out.
Roles belong to your organization
Section titled “Roles belong to your organization”Every role in Vendorica is your organization’s own. When your organization was created, its roles were copied from a set of templates — a starting point, not a fixed menu. You can rename them, change what they grant, add new ones and retire ones you do not use, and nothing you do affects any other organization.
This matters more than it sounds. Most compliance products give you a short fixed ladder — admin, editor, viewer — and expect your governance model to bend to it. Yours does not have to: if your policy distinguishes a vendor owner from a risk owner from a control owner, you can hold exactly that distinction.
Some roles are marked as having come from a template. That marking is provenance, not a lock — it records where the role came from, and you can still edit it.
Permissions are the shared vocabulary
Section titled “Permissions are the shared vocabulary”What a role grants is drawn from a fixed vocabulary of permissions — “create a vendor”, “approve an assessment”, and so on. The vocabulary is the same for everyone; the way you combine it into roles is yours.
The practical consequence: you cannot invent a new kind of permission, but you can build any role out of the ones that exist. If something you need has no permission behind it, that is a gap for us to close — please tell us.
Editing a role safely
Section titled “Editing a role safely”Changes take effect immediately for everyone holding the role. Two habits worth keeping:
- Change the role, not the person. If one person needs something extra, resist granting it to the role everyone shares. Make a role that describes the job.
- Check who holds it first. The member list shows you, and a role held by one person is a very different edit from a role held by forty.
What roles do not control
Section titled “What roles do not control”Roles govern what you can do inside an organization. They do not decide which features your organization has — that comes from your plan and any add-ons. If a page is missing rather than refusing you, it is a plan question, not a permissions one; see vendorica.com/pricing.