Skip to main content

Read-Only and Restricted-View Roles

Use this article to understand how Read-only and Restricted-view roles work, which roles are available, and how to assign them.

💡 New to roles in Drata? Start with the Roles and permissions overview before reading this article.


How these roles work

Most Drata roles are available in up to three versions: a base role, a Read-only version, and a Restricted-view version. Each is a separate, assignable role — not a toggle or setting on an existing role.

Role type

What it does

Base role

Full read and write access to all pages available to that role.

Read-only

Access to the same pages as the base role, but limited to viewing, filtering, and downloading. Users in this role cannot create, edit, or delete resources.

Restricted-view

Access limited to only the items the user owns or is assigned to.

Available for Control Manager and Risk Manager only.

ℹ️ Note: You can assign more than one role to the same user, as long as they are not variant of the same role family. For more information, refer to the following note.

⚠️ Known limitation: Drata currently blocks assigning both the Read-only and Restricted-view variant of the same role (Control Manager or Risk Manager) to a user directly. However, both variants can still be added to a user through IdP group mapping, or may already exist on a user if they were assigned before this restriction was introduced. Because these two variants grant conflicting access — one gives read access to everything, the other limits access to only owned items — a user with both may end up with inconsistent permissions. We recommend reviewing any users with both roles assigned.

Read-only roles

Role

What users can do

Read-only Admin

View, filter, and download across the entire application

Read-only

Access Reviewer

View access reviews and applications

Read-only

Control Manager

View controls and related evidence

Read-only

Dev Ops Engineer

View Compliance as Code tasks, test results, and infrastructure findings

Read-only

Information Security Lead

View security posture, controls, and compliance evidence

Read-only Personnel Compliance Manager

View background checks, employee status, and personnel compliance

Read-only

Policy Manager

View and download policies

Read-only Risk Manager

View the risk register and risk details

Read-only

Risk Register Owner

View risks within the risk registers they own

Read-only

Trust Center Manager

View Trust Center insights, access requests, and settings

Restricted-view roles

Role

What users can access

Restricted-view

Admin Control Manager

Only the controls they own or are assigned to for tasks or required approvals

Restricted-view

Risk Manager

Only the risks they own or are assigned to for task


Note for existing users

If your account previously used read-only or restricted access settings through role toggles, those users have been automatically migrated to the corresponding role.

Did this answer your question?