RiskPilot Website FR GitHub

Users and roles #

Available Reserved for administrators

Purpose and permissions #

From Settings → Users, the administrator manages the accounts of his organization. The fields are first name, last name, email, initial password, roles and status.

Create, modify, deactivate #

Create an account with a unique address and the minimum roles required. A modification adjusts identity, roles or activity. Deletion makes sense: prefer deactivation to preserve the assignments. The available roles follow the hierarchy Admin, Risk manager, Auditor and Action manager.

Research, errors and practices #

Filter the list before editing. An identifier from another tenant is refused. Do not share accounts; Enforce a strong initial password and then prompt the user to enable MFA.

See also #

Profile, MFA and sessions · Audit log

Role matrix #

RolePrimary Responsibility
Super Adminseveral organizations
Administratortenant accounts and settings
Risk managerinventory, risks and treatments
Listenerinsurance and authorized consultation
Responsible for actionexecution of assigned actions

Complete procedure #

Open Settings → Users, enter first name, last name, email and initial password, then assign the minimum roles. Activate the account, register and request a password change with MFA activation.

Before deactivation, reassign risks, actions, documents and deadlines. Logical deletion retains historical responsibilities; never reuse an account for another person.

Checks and errors #

An address already in use requires searching for the existing account. An invisible user can belong to another tenant or be inactive. For an impossible connection, successively check status, lock, password, MFA and sessions.

Example: an audit consultant receives Auditor, not Administrator. A Remediation Manager receives Action Manager.