Governance & evidence
Team, roles and access control
Compliance work is rarely done by one person. This guide covers who can do what in EuroCompliant: inviting team members, the three roles that govern their access, department structure, and the two account-security layers, two-factor authentication and single sign-on.
Transcript
Not everyone in your organisation needs full access to your compliance data. This is how you invite your team and control exactly what each person can see and do.
GDPR Article 32 requires technical and organisational security measures appropriate to risk. Role-based access is one of those measures: people only see what their job requires.
Open Settings and go to Team & Access. This is the member list, and it is where invitations, roles, and active members all live.
Invite someone with a name, an email, and a role. Five built-in roles exist: Viewer is read only, Auditor is read only and additionally blocked from every mutating action platform-wide, Editor can work obligations and evidence, Department Admin manages their own department, and Admin runs the whole workspace. The invitation goes out by email.
Each role maps to what the person can touch. The role badge shows on every member, and you can change a role later as the person's responsibilities change.
Need something more specific than the built-in five? Settings, Custom Roles lets you build your own from individual permissions, like a role that can only submit or review a FRIA for one department.
A member isn't limited to one role. Back on Team and Access, add roles to stack on top of a person's primary one, and each additional grant can carry its own department scope, so someone can be an Editor company-wide, plus this custom role, but only within one department.
For a whole team rather than one person at a time, create a Group instead: scope it to a department (or leave it unrestricted to span all of them), add members, and grant it roles. Everyone in the group inherits its grants on top of whatever they already have individually.
Departments themselves live under the same Team and Access area: a real hierarchy, not just a label, with parent and child departments and their own member, system and open-item counts.
That department scoping rolls up automatically wherever it's used, on an individual grant or a group's: restrict access to a parent department and it reaches everything under it too, sub-departments included. Separately, anyone whose overall access spans more than one department gets a filter in the sidebar to narrow their own view, a convenience only, since every list is still enforced server-side to exactly what they're allowed to see regardless of what's selected.
When you're onboarding a large organisation, one invite at a time won't cut it. Under the same Team and Access area, Bulk Import takes a CSV of members, groups, or custom roles (role, department, group memberships and extra role grants per row) and reports exactly which rows landed and which need fixing. Re-running it skips what already exists, so fixing a few rows and re-uploading is safe.
And when the identity provider itself manages who belongs, SCIM keeps users and groups in sync automatically: provision a new hire, update them, deactivate them on leaving. Deactivation is a hard lockout: the moment someone is removed from the identity provider, they're cut off from every login and every session already open, no manual offboarding needed.
Two-factor authentication is a real TOTP setup. Open the security settings and scan the QR code with an authenticator app to add a second factor to your own account.
Built-in or custom roles, stacked individually or inherited through a group, scoped to a department or company-wide, with two-factor on top: your compliance workspace has the same access discipline you would expect from the tooling it is protecting.
Why this is required
GDPR Article 32 requires technical and organisational measures appropriate to risk, and access control is one of the most basic of those measures: not everyone in your organisation needs, or should have, full administrative access to your compliance data. ISO 27001 Annex A.5 and A.6 make the same point directly, covering access control policy and personnel security.
Two-factor authentication and single sign-on aren't just good practice, they're frequently the first thing a customer's security questionnaire or an auditor asks about. Being able to say yes, with an enforcement toggle that applies it organisation-wide, closes that question quickly.
What EuroCompliant does
Below the account owner: Admin, Department Admin, Editor, Viewer, and Auditor (read-only, additionally blocked from every mutating action platform-wide) are built in, or you can build your own custom role from a granular permission registry covering every action in the platform. Team members are invited by email, accept via a link, and set their own password.
A team member isn't limited to one role. Grant additional roles directly, or create a user group that carries its own role grants, a group can span a single department or several, independent of any member's own home department.
Departments can be nested, and any role or group grant restricted to a department automatically rolls up to include everything under it: a department head scoped to a parent department sees their own team and every sub-department beneath it, not just their own literal department_id.
A policy that requires staff acknowledgment can be targeted at specific departments or groups instead of the whole company. Only the people in that audience see it in their My Compliance page, are emailed acknowledgment requests, or appear in the acknowledgment matrix, so an engineering-only policy stays engineering-only, and ISO 27001 A.6.3 evidence is scoped to exactly who was actually asked to read it.
Onboarding a large organisation doesn't mean one invite at a time. Bulk Import (Settings → Team → Bulk Import) provisions team members, groups, and custom roles from a CSV: each row sets the role, department, group memberships, and additional role grants, with per-row reporting and the same plan-limit and role-safety rules as an individual invite. Re-running an import skips what already exists, so it is safe to fix a few rows and re-upload.
Single sign-on can also be fully automated with SCIM. Connect an identity provider (Okta, Microsoft Entra ID, Google, Keycloak) to the SCIM 2.0 endpoints and users and groups stay in sync automatically. When someone is removed or deactivated in the identity provider they are locked out of every login and every existing session immediately. No manual offboarding, no stale access. The platform's SSO flows (Google OAuth, OIDC, or SAML depending on your plan) share the same per-tenant identity provider configuration.
Anyone whose access spans more than one department gets a global department filter in the sidebar to narrow their own view on demand, purely a convenience lens. Every list is independently re-enforced server-side to exactly what that person is actually allowed to see, whether or not they've touched the filter.
Departments also show stats per department: members, AI systems, pending DSARs, active breaches, and processors without a signed DPA, useful for spotting which part of the business is behind.
Two-factor authentication is a full TOTP setup: scan a QR code with an authenticator app, confirm a code, done. Admins can additionally enforce 2FA for everyone in the organisation. Single sign-on (Google OAuth, OIDC or SAML, depending on your plan) is configured separately, and is only available to the account owner, not to team members with the Admin role.
Walking through it
Invite a team member
Name, email, role, and optionally a department. They receive an email invite link and set their own password.
Open /settings/team →Assign the right role, or build a custom one
Start from a built-in role, or define your own from the permission registry when you need something more granular, for example a role that can only submit or review a FRIA for one department.
Open /settings/team?tab=roles →Group members who share access, across departments if needed
Create a group, scope its department_ids (or leave it unrestricted), grant it roles, and add members. Everyone in the group inherits its grants on top of their own.
Open /settings/team?tab=groups →Structure your departments
Build the hierarchy that matches your organisation, then assign each team member to one. Department stats make it easy to see where the gaps are.
Open /settings/team?tab=departments →Turn on two-factor authentication
Set it up for your own account under My Security, then consider enforcing it organisation-wide from Organisation Security.
Open /account/security →Bulk-provision a large team
Settings → Team → Bulk Import accepts a CSV of team members (role, department, groups), groups, and custom roles, thousands of users in one upload, with per-row errors reported so you can fix and re-run.
Open /settings/team?tab=bulk-import →Connect SCIM for IdP-driven access
Under SSO providers, generate a SCIM token and point your identity provider at the /scim/v2 endpoints. Users and groups sync automatically, and deactivating someone in the IdP locks them out immediately.
Open /settings/auth →The law
Security of processing
Technical and organisational measures appropriate to risk, including access control.
Organisational controls
Includes access control policy and management of user access rights.
People controls
Includes screening, terms of employment, and access changes on termination.
Frequently asked
Can an Admin-role team member configure SSO?
No. SSO configuration is restricted to the original account owner, regardless of what role other team members hold. This is a deliberate control-plane boundary, not a bug: if an Admin needs SSO changed, the owner has to make them.
What happens to a department's members if I delete it?
They're unassigned rather than removed from the team, and any child departments move up a level. Deleting a department never deletes people or their access.
How does SCIM deactivation work with an existing login?
Deactivation sets the member's account to suspended. That is enforced at token verification time, so even a person who is already logged in has their existing session stopped immediately. They cannot continue to use the platform after the identity provider removes them.
Can a policy be sent to only part of the team?
Yes. On any policy that requires staff acknowledgment you can choose specific departments and/or groups as the audience. Only members in that audience are asked to acknowledge; the matrix and the My Compliance page reflect exactly that audience.
Related guides
Getting started
How EuroCompliant is structured, why the work has to happen in a particular order, and what the dashboard is telling you.
Evidence vault & audit trail
Turning completed checklist items into artefacts a regulator can inspect, and the logging duties behind Articles 12 and 26.
Integrations, scanning and vendor risk
Connecting your infrastructure for automated scanning, wiring up notifications, and tracking third-party risk.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial