💡 New to roles in Drata? Start with the Roles and permissions overview before reading this article.
How these roles work
Most Drata roles are available in up to three versions: a base role, a Read-only version, and a Restricted-view version. Each is a separate, assignable role — not a toggle or setting on an existing role.
Role type | What it does |
Base role | Full read and write access to all pages available to that role. |
Read-only | Access to the same pages as the base role, but limited to viewing, filtering, and downloading. Users in this role cannot create, edit, or delete resources. |
Restricted-view | Access limited to only the items the user owns or is assigned to. Available for Control Manager and Risk Manager only. |
ℹ️ Note: You can assign more than one role to the same user.
For example, assigning both Control Manager (Restricted-view) and Control Manager (Read-only) limits the user to only the controls they own, with view-only access to those controls.
Read-only roles
Role | What users can do |
Read-only Admin | View, filter, and download across the entire application |
Read-only Access Reviewer | View access reviews and applications |
Read-only Control Manager | View controls and related evidence |
Read-only Dev Ops Engineer | View Compliance as Code tasks, test results, and infrastructure findings |
Read-only Information Security Lead | View security posture, controls, and compliance evidence |
Read-only Personnel Compliance Manager | View background checks, employee status, and personnel compliance |
Read-only Policy Manager | View and download policies |
Read-only Risk Manager | View the risk register and risk details |
Read-only Risk Register Owner | View risks within the risk registers they own |
Read-only Trust Center Manager | View Trust Center insights, access requests, and settings |
Restricted-view roles
Role | What users can access |
Restricted-view Admin Control Manager | Only the controls they own or are assigned to for tasks or required approvals |
Restricted-view Risk Manager | Only the risks they own or are assigned to for task |
Note for existing users
If your account previously used read-only or restricted access settings through role toggles, those users have been automatically migrated to the corresponding role.
No action is required.
