💡 New to roles in Drata? Start with the Roles and permissions overview before reading this article.
How these roles work
Most Drata roles are available in up to three versions: a base role, a Read-only version, and a Restricted-view version. Each is a separate, assignable role — not a toggle or setting on an existing role.
Role type | What it does |
Base role | Full read and write access to all pages available to that role. |
Read-only | Access to the same pages as the base role, but limited to viewing, filtering, and downloading. Users in this role cannot create, edit, or delete resources. |
Restricted-view | Access limited to only the items the user owns or is assigned to. Available for Control Manager and Risk Manager only. |
ℹ️ Note: You can assign more than one role to the same user, as long as they are not variant of the same role family. For more information, refer to the following note.
⚠️ Known limitation: Drata currently blocks assigning both the Read-only and Restricted-view variant of the same role (Control Manager or Risk Manager) to a user directly. However, both variants can still be added to a user through IdP group mapping, or may already exist on a user if they were assigned before this restriction was introduced. Because these two variants grant conflicting access — one gives read access to everything, the other limits access to only owned items — a user with both may end up with inconsistent permissions. We recommend reviewing any users with both roles assigned.
Read-only roles
Role | What users can do |
Read-only Admin | View, filter, and download across the entire application |
Read-only Access Reviewer | View access reviews and applications |
Read-only Control Manager | View controls and related evidence |
Read-only Dev Ops Engineer | View Compliance as Code tasks, test results, and infrastructure findings |
Read-only Information Security Lead | View security posture, controls, and compliance evidence |
Read-only Personnel Compliance Manager | View background checks, employee status, and personnel compliance |
Read-only Policy Manager | View and download policies |
Read-only Risk Manager | View the risk register and risk details |
Read-only Risk Register Owner | View risks within the risk registers they own |
Read-only Trust Center Manager | View Trust Center insights, access requests, and settings |
Restricted-view roles
Role | What users can access |
Restricted-view Admin Control Manager | Only the controls they own or are assigned to for tasks or required approvals |
Restricted-view Risk Manager | Only the risks they own or are assigned to for task |
Note for existing users
If your account previously used read-only or restricted access settings through role toggles, those users have been automatically migrated to the corresponding role.
