Access Domains

Any user could see any third party, regardless of whether it was their responsibility. Access can now be limited per third party, and will become more granular.

Key Enhancements

  • access per third party: a user only sees the third parties they have access to. Restricted ones do not appear in searches, dropdowns, reports or dashboards, cannot be linked to assessments, issues or action plans, and are refused if reached by direct link.

  • access per risk domain: restrict access to individual risk domains within a third party, so a team responsible for one domain cannot edit another team's, on the same third party.

  • start with no access: add a user to specific third parties only, so they see nothing by default. The existing model, where access to everything is narrowed down per third party, stays available.

  • a cleaner permission list: role management shows only the permissions for modules and features active on your environment. Nothing is removed, and roles keep permissions that are hidden.

Share update with 0 linked conversations as well

Upvoters
Board

Roadmap 2026

ETA
Nov 30, 2026
Date

21 days ago

Author

Kamilla Dajani

Subscribe to post

Get notified by email when there are changes.