Managing Roles and Security
How to set up user roles, permissions, and POPIA-compliant data governance settings.
Overview
The Roles & Security module ensures the right people have the right access. It supports role-based access control (RBAC), multi-factor authentication, POPIA-compliant data governance, and comprehensive access logging. This guide covers creating roles, assigning permissions, onboarding users, and maintaining security.
Step-by-Step Guide
Step 1: Create Role Definitions
Navigate to "Administration" > "Roles & Security." Define roles that match your organisational structure — for example, Procurement Officer, Evaluation Committee Member, Finance Approver, System Administrator, and Read-Only Auditor. Each role defines a scope of access rather than assignment to a specific person, ensuring permissions survive staff changes.
Step 2: Assign Permissions per Role
For each role, configure granular permissions across the platform. Permissions are organised by module (Tendering, Evaluation, Contracts, Audit Vault, etc.) and action (View, Create, Edit, Approve, Export). Apply the principle of least privilege — grant only the minimum access required for the role's function. The system validates that no role combination can create a segregation-of-duties conflict.
Step 3: Invite Users and Assign Roles
Invite users by email address. Each invited user receives an activation link and sets up their account. Assign one or more roles to each user. Users can hold multiple roles where appropriate, but the system flags any combinations that create conflict-of-interest or segregation-of-duties risks. Users must accept the platform's terms of use and data processing agreement before accessing the system.
Step 4: Enable Multi-Factor Authentication
MFA is mandatory for all administrative roles and strongly recommended for all users. Configure MFA methods — authenticator app (preferred), SMS OTP, or hardware security key. Enforce MFA at the organisation level through the Security Settings. Users who do not set up MFA within the configured grace period are automatically suspended.
Step 5: Review Access Logs
Monitor user activity through the Access Log dashboard. Logs capture login attempts, module access, data exports, and configuration changes. Filter by user, date, module, or action type. The logs are immutable and stored in the Audit Vault. Schedule periodic access reviews to identify dormant accounts, unusual access patterns, or permission creep.
Tips & Best Practices
- Follow the least-privilege principle — grant users only the access they need for their current role, not what they might need in future.
- Review user access quarterly and after any organisational changes such as promotions, transfers, or departures.
- Enable MFA for all admin and Approver roles without exception — this is a non-negotiable security baseline.
- Use role-based access rather than individual permissions to simplify onboarding, offboarding, and audit compliance.
Related Features
Roles & Security — Features page →