Roles & Permissions allows administrators to control what users can do across Warrant OS by assigning permissions based on their responsibilities. This helps ensure users have access only to the features they need while supporting a secure and efficient review process.
With Roles & Permissions, you can create custom roles, assign them to users or groups, and manage access across your organization from a single location.
Note: Roles & Permissions is an optional feature. Your organization's existing access settings remain unchanged until capability permissions are enabled.
Access Roles & Permissions
To access Roles & Permissions:
Click Settings in the left sidebar.
Under Members, select Roles.
From this page, you can configure permission settings, create roles, and manage role assignments.
Configure permission policies
At the top of the page are three organization-wide settings that control how permissions are enforced.
Separation of duties (Maker-Checker)
When enabled, users cannot approve assets they submitted themselves. If a user is assigned both Submit and Approve capabilities, a written rationale is required. Any administrator override must also include a justification.
This setting only takes effect while Enforce capability permissions is on.
This helps support independent review processes and strengthens compliance controls.
Enforce capability permissions
When enabled, users can perform only the capabilities granted through their assigned roles. Any capability that has not been assigned is automatically denied.
If this setting is disabled, your organization's existing access behavior remains unchanged.
⚠️ Turning this on requires confirmation — enabling it makes access deny-by-default for the whole company immediately, so anyone without a role assignment is locked out the moment you confirm.
Allow all members to delete
When enabled, every member can permanently delete assets and versions, whatever their roles say. Leave it off to grant delete access only through the Delete capability on a role. Archive is always available to everyone.
Create a role
Roles are made up of capabilities that determine what users can do throughout Warrant OS. Available capabilities include:
Capability | Allows users to... |
View | View assets and compliance results. |
Scan | Run compliance scans on assets. |
Review | Review assets in an approval (dismiss, restore, or mark a finding relevant). |
Comment | Add inline comments on scan findings. |
Relevancy Feedback | Give thumbs up or down relevancy feedback on scan findings. Votes help Warrant tune how strictly each policy is applied for your company. |
Create / Upload | Create or upload assets. |
Submit | Submit assets for approval. |
Approve | Approve assets and appear in the approver picker. |
View Brand Portal | See the Brand Portal: libraries, disclosures, products and brands. Implied by View until a role is granted it explicitly. |
Manage Brand Portal | Create, edit, import and archive libraries and their records, disclosures, products and brands, without full admin access. |
Delete | Permanently delete assets and versions (archive is always available). |
Admin | Manage roles, permissions, and company configuration. |
Reassign | Reassign approvals to a different reviewer or group. |
To create a role:
Click New role.
Enter a name for the role.
Add a description.
Click Create.
Check the capabilities the role grants in the matrix. Each checkbox saves as soon as you click it.
The Roles table provides a permission matrix, making it easy to compare the capabilities assigned to each role.
Roles and assignments can only be edited while Enforce capability permissions is on. Built-in roles are marked System and cannot be deleted or renamed, but their capabilities can be changed.
Pause a role (Draft or Inactive)
Each role has a status menu under its name in the matrix: Active, Draft or Inactive. A Draft or Inactive role can still be edited and assigned, but grants nothing until you switch it back to Active. Use Draft to prepare a role and its assignments before switching it on in one step.
If pausing a role would leave people with no access or remove someone's admin rights, Warrant asks you to confirm and names who is affected. You cannot pause a role that would remove your own admin access.
Groups have the same Status setting in Settings → Members → Groups. Members of a paused group keep their place in it but get nothing from it: no roles, access, admin rights or approvals.
Assign a role
Roles can be assigned to individual users or groups.
To assign a role:
In the Assignments section, click Assign role.
Choose the role you want to assign.
Under Assign to, choose User or Group, then select the user or group.
If prompted, provide a rationale.
Click Assign.
Users who belong to a group automatically inherit the roles assigned to that group.
Ready-to-use role templates
Warrant includes five ready-to-use role templates to help you get started:
Submitter – Can view, scan, and comment on assets. Cannot submit for approval or approve.
Creator – Can upload, scan, comment on, and submit assets for approval. Cannot review, approve, or delete.
Proofreader – Can view, review, and comment on assets, and give relevancy feedback. Cannot approve, create, or submit.
LOB Reviewer – Can view, scan, review, comment on, and approve assets, and give relevancy feedback. Cannot create or submit.
Compliance Admin – Full access, including creating, submitting, approving, and deleting assets and managing roles and permissions.
You can use these roles as they are or create additional custom roles to fit your organization's workflow.
Export an access review
To download a report of your organization's current role assignments, click Export access review in the Assignments section.
The report is exported as a CSV file and can be used for periodic access reviews or compliance audits.
Review role assignments
The Assignments section provides a complete view of role assignments across your organization. From here, you can:
View existing role assignments.
Assign additional roles.
Edit an assignment, including its rationale.
Remove role assignments.
Export an access review for auditing or record-keeping.
How Roles & Permissions affects users
When capability permissions are enabled, users only have access to the actions included in their assigned roles.
Depending on their permissions, some actions may be hidden or unavailable throughout Warrant OS. For example, only users with approval permissions can be selected as approvers, only users with reassign permissions can move an approval to someone else, and users without permission to create, upload, scan, or submit assets won't see those actions available.