Skip to main content
    Team & Collaboration
    5 min readUpdated 2025-01-25

    User Roles & Permissions

    Comprehensive guide to Klarvo's role-based access control system and permission levels.

    User Roles & Permissions

    Klarvo uses role-based access control (RBAC) to ensure users have appropriate access to compliance data.

    Available Roles

    #### Admin

    Full platform access

    AreaPermissions
    AI SystemsCreate, Read, Update, Delete
    EvidenceAll actions + approve
    TasksAll actions + reassign
    TeamInvite, manage, remove
    SettingsAll including billing
    IntegrationsConfigure all
    ReportsGenerate any

    #### Compliance Owner

    Manages the compliance program

    AreaPermissions
    AI SystemsCreate, Read, Update, Delete
    EvidenceAll actions + approve
    TasksAll actions
    TeamInvite (except admin)
    SettingsOrg settings, not billing
    ReportsGenerate any

    #### System Owner

    Owns specific AI systems

    AreaPermissions
    AI SystemsRead/Update own systems
    EvidenceUpload for own systems
    TasksComplete assigned tasks
    TeamView only
    SettingsPersonal settings only
    ReportsOwn systems only

    #### Reviewer/Approver

    Reviews and approves compliance artifacts

    AreaPermissions
    AI SystemsRead all
    EvidenceRead + approve
    AssessmentsReview + approve
    PoliciesReview + approve
    TasksView + comment

    #### Viewer

    Read-only access

    AreaPermissions
    AI SystemsRead only
    EvidenceView only
    TasksView only
    ReportsView shared reports

    Permission Matrix

    CapabilityAdminComp. OwnerSys. OwnerReviewerViewer
    Create AI systems
    Edit any AI system
    Edit own AI systems
    Upload evidence
    Approve evidence
    Create tasks
    Complete tasks
    Invite members
    Manage billing
    Export reports

    Cannot invite Admin users

    Own systems only

    Auditor Role (Special)

    For external auditors, Klarvo offers a restricted "Auditor" view:

  1. Read-only access to shared areas
  2. No editing capabilities
  3. Export-ready document views
  4. Time-limited access tokens
  5. Watermarked document views
  6. Custom Roles (Enterprise)

    Enterprise plans support custom role definitions:

  7. Start from a base role template
  8. Add or remove specific permissions
  9. Create department-specific variants
  10. Apply to user groups
  11. Best Practices

    🔒 Least privilege: Assign minimum necessary access
    👥 Separation of duties: Different people for create vs. approve
    📋 Regular audits: Review access quarterly
    🚪 Prompt offboarding**: Remove access same-day