Most compliance work crosses roles: a regulatory affairs lead sees the rule, legal reads the text, operations closes the gap, the CISO signs off on evidence. ACE roles are scoped so each person gets exactly the access they need.
| Role | Can | Cannot |
|---|---|---|
| Owner | Everything: billing, workspace settings, member management, all read/write. | — |
| Editor | Read all sources, run gap analyses, create and assign remediation, export reports. | Manage billing, remove workspace. |
| Reviewer | Read sources, score adjustments, comment on gap analyses, sign off on evidence. | Create sources, edit remediation, export reports. |
| Viewer | Read sources and gap analyses; receive assigned notifications. | Modify anything. |
New members see the workspace's primary sources and recent activity on their first login. They do not see other workspaces in your tenant, and they cannot access sources or items outside their role's scope. All member actions are logged in the audit trail accessible to Owners.
You have walked through every core workflow in ACE. From here, the typical first-week path is: add the remaining jurisdictions your team covers, tune the default notification rules, and assign ownership of the gap queue.