Assign Roles for Sprinto Workflow Actions

Learn how to assign roles in Sprinto to ensure accountability for workflow checks, evidence submission, and compliance actions.

Sprinto triggers a workflow check when required compliance roles are unassigned or missing. To resolve these checks and ensure continued evidence collection, administrators must assign designated users to the necessary roles.

Assigning roles ensures the right people are responsible for security and compliance tasks, such as submitting evidence, reviewing access, and managing incidents. These roles also enable accurate ownership mapping across controls, policies, and monitors.


When is this check triggered?

This check is triggered when one or more of the following roles are not assigned within the organisation:

Role
Description

Information Security Officer

Responsible for overseeing the overall compliance programme.

Data Privacy Officer

Manages privacy-related matters, including data subject rights.

Infrastructure Owner

Oversees cloud and on-premises infrastructure.

Access Manager

Manages access reviews and critical system access provisioning.

Incident Manager

Responsible for reviewing and closing reported security incidents.

Risk Manager

Conducts risk assessments and manages risk remediation plans.

Vulnerability Manager

Handles vulnerability management and remediation efforts.


How to assign roles

  1. Navigate to the People → Staff section in the Sprinto dashboard.

  2. Locate the relevant staff member and click Edit.

  3. In the role assignment section, select the appropriate role(s) based on the table above.

  4. Ensure that the staff member’s reporting manager and job role are also updated — these fields are mandatory for this check to pass.

  5. Click Save to update the profile.

Sprinto will automatically mark the check as resolved once all required roles are assigned and mapped to active employees.


Notes:

  • You can assign multiple roles to a single person if needed.

  • If any of the above roles are intentionally unassigned (e.g., small teams), you can mark them as Not Applicable through a manual override and add supporting evidence.

  • Sprinto uses assigned roles to manage task assignments across evidence workflows, control mapping, and auditor coordination.

Last updated