> For the complete documentation index, see [llms.txt](https://docs.sprinto.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sprinto.com/dashboard/user-management/user-management-collaborator.md).

# User Management

Learn how to assign, manage, and revoke access in Sprinto for seamless task delegation and compliance tracking.

## User Management

The **User Management** section in **Settings** controls who can access the Sprinto Admin Portal and what they are able to do once inside. Every user is assigned a single **access role**, which determines the areas of Sprinto they can view or edit.

Use this section to add users, assign or change access roles, and grant granular area-level permissions.

> **Note:** Access roles control what a user can do inside the Sprinto Admin Portal. They are separate from **job roles** (for example, Engineer or Manager), which are staff attributes managed in Data Library > People, and from **security roles** (for example, CISO or Privacy Officer), which assign ownership of compliance responsibilities.

***

### Before you begin

* You must be logged in to the Sprinto Admin Portal with an access role that permits editing **Settings > User Management**.
* The person you want to add must already exist as a staff member in Sprinto. If they do not, add them first via **Data Library > People**.
* A staff member can hold only one access role at a time. Staff who already have a role assigned will not appear in the **Select staff** search when adding a user.

***

### Access roles

Sprinto provides five access roles.

| Access role       | Access type            | What the user can do                                                                          |
| ----------------- | ---------------------- | --------------------------------------------------------------------------------------------- |
| **Collaborator**  | Task-only access       | View and work only on tasks and checks assigned to them.                                      |
| **Viewer**        | Read-only access       | View specific areas of Sprinto based on the permissions granted, but cannot make any changes. |
| **Scoped Editor** | Ownership-based access | View and take action only on entities they own, create, or are explicitly assigned to.        |
| **Custom**        | Custom access          | Access any area within the app, at a level you define per area.                               |
| **Admin**         | Full access            | Complete access to manage the organization on Sprinto.                                        |

#### Choosing the right role

* **Collaborator** — for staff who only need to resolve checks assigned to them, such as an engineer fixing a single infrastructure check. This is the narrowest role.
* **Viewer** — for stakeholders who need visibility without the ability to change anything, such as senior management reviewing compliance posture, or an internal auditor.
* **Scoped Editor** — for owners of a defined set of entities, such as a risk owner or vendor owner who should act on their own records but not the whole register.
* **Custom** — for anyone whose responsibilities do not map cleanly onto the roles above, such as an HR representative who needs edit access to People and Trainings but nothing else.
* **Admin** — for compliance program owners who administer Sprinto itself. Grant this sparingly.

> **Warning:** **Admin** grants complete access, including the ability to manage other users' access. Following the principle of least privilege, assign the narrowest role that allows someone to do their job, and use **Custom** rather than **Admin** where only a few areas are needed.

***

### View existing users and their access

1. Go to **Settings > User Management**. The page lists every user with access to the Admin Portal.
2. Review the columns:
   * **User** — the user's name and email address.
   * **Access Role** — the role currently assigned.
   * **Has access to** — the areas the user can reach, grouped by permission level (**Edit** and **View**). Where a user has access to more areas than fit in the row, a counter such as **+36** is shown. Users with the **Scoped Editor** role show **Assigned entities** instead of a list of areas, because their access follows entity ownership rather than areas.
3. Use **View: All** to switch between saved views, **Filter** to narrow the list, or the search icon to find a specific user.
4. Click the **>** chevron at the end of a row to open that user's access details.

***

### Add a user and assign an access role

1. Go to **Settings > User Management**.
2. Click **Add user** in the top-right corner. The **Add user** panel opens.
3. Under **Select staff**, type at least three letters of the person's name or email, then select them from the results.

   Staff who already have an access role assigned do not appear in this list. To change an existing user's role, open their row from the User Management list instead.
4. Under **Access role**, select one of **Collaborator**, **Viewer**, **Scoped Editor**, **Custom**, or **Admin**.
5. Complete the role-specific step:
   * **Collaborator**, **Scoped Editor**, or **Admin** — no further configuration is required. These roles derive access from task assignment, entity ownership, or full access respectively.
   * **Viewer** or **Custom** — continue to **Configure user access** and set permissions per area, as described in the next section.
6. Click **Add user**.

The user is added to the User Management list with the role you selected.

***

### Configure area-level access

The **Configure user access** step applies to the **Viewer** and **Custom** roles, where access is granted area by area.

1. Confirm the user shown at the top of the panel is the correct person.
2. For each area, select a permission level:
   * **None** — the area is hidden from the user.
   * **View** — the user can see the area but cannot make changes.
   * **Edit** — the user can see the area and take action in it.
3. To apply one level across every area at once, use **Set all to: View** or **Set all to: Edit** at the top of the **Area** list, then adjust individual areas as needed.
4. Expand **Data Library** or **Settings** using the **>** chevron to set permissions on their sub-areas individually. The counter beside each shows how many of its sub-areas are currently granted, for example **0 of 12**.
5. Check the running total at the bottom of the panel — for example, **0 of 41 areas granted** — to confirm the scope you have configured.
6. Click **Add user** to save, or **Back** to return to the role selection step.

#### Available areas

### Available areas

Permissions can be set on 41 areas in total. Areas with a count can be expanded to set permissions on each sub-area individually.

#### Top-level areas

| Area              | What it covers                                                                                   |
| ----------------- | ------------------------------------------------------------------------------------------------ |
| Audits            | Compliance, internal, and custom audits, audit requirements, evidence review, and audit reports. |
| Policies          | Policy creation, approval, versioning, acknowledgements, and policy registers.                   |
| Risks             | Risk registers, risk scoring, treatments, and risk assessments.                                  |
| Compliance        | Frameworks, criteria, controls, and control-to-criteria mapping.                                 |
| Data Library (12) | Staff, assets, and operational records that feed compliance checks. See below.                   |
| Monitoring        | Automated and workflow checks, check status, evidence submission, and exceptions.                |
| AI Toolkit        | Sprinto's AI-assisted features and agents.                                                       |
| AI management     | Governance of the organization's own AI systems, including AI system assessments.                |
| Settings (22)     | Account, access, and platform configuration. See below.                                          |

#### Data Library sub-areas

| Sub-area          | What it covers                                                           |
| ----------------- | ------------------------------------------------------------------------ |
| People            | Staff records, job roles, security roles, scoping, and onboarding.       |
| Trainings         | InfoSec training providers, campaigns, and completion tracking.          |
| Staff devices     | Endpoint inventory and device health checks.                             |
| Access            | Critical access systems, access controls, and access reviews.            |
| Vendors           | Vendor records, due diligence, risk scoring, and documents.              |
| Change management | Code repositories, ticketing systems, and change approval evidence.      |
| Vulnerabilities   | Vulnerability findings from scanners and pentests, and remediation SLAs. |
| Infrastructure    | Connected cloud accounts and infrastructure resource classification.     |
| Incidents         | Incident reporting, severity, and closure.                               |
| Asset register    | Manually tracked organizational assets.                                  |
| Reviews           | Access reviews and management reviews.                                   |
| Reports           | Generated compliance, risk, and vendor reports.                          |

#### Settings sub-areas

| Sub-area             | What it covers                                                              |
| -------------------- | --------------------------------------------------------------------------- |
| Integrations         | Connecting and managing third-party service integrations.                   |
| Partner Integrations | Audit partner and reseller integrations.                                    |
| Email Insights       | Configure Email Insights                                                    |
| Company              | Company profile, including display name, legal name, and logo.              |
| User Management      | Admin Portal access roles and area-level permissions.                       |
| Notifications        | Notification channels and delivery preferences.                             |
| Activity log         | Audit trail of actions taken in the Admin Portal.                           |
| Employee portal      | Configuration of the staff-facing Employee Portal.                          |
| Special cases        | Exceptions recorded against failing checks and monitors.                    |
| SSO Login            | Single sign-on provider setup and domain configuration.                     |
| Developer API        | API access and credentials for programmatic use.                            |
| Sprinto AI           | Configuration of Sprinto's AI capabilities.                                 |
| Beta Features        | Opt-in access to features in beta.                                          |
| Custom fields        | Custom attributes on supported entity types.                                |
| Scoring methods      | Risk scoring formulas and rating scales.                                    |
| Automations          | Rule-based automation of compliance workflows.                              |
| Credentials          | Stored credentials used by integrations.                                    |
| Billing              | Subscription plan and billing details.                                      |
| Customer Rewards     | Referral rewards                                                            |
| Zones                | Segregated compliance environments for multiple business units or entities. |
| Approval Paths       | Approval workflows and approver sequencing.                                 |
| Task Sync            | Syncing Sprinto tasks with external ticketing systems.                      |

***

### Support

For help with user access, contact the Sprinto support team at <support@sprinto.com>.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.sprinto.com/dashboard/user-management/user-management-collaborator.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
