CSFaaS supports the people who direct, perform and review cybersecurity governance, risk and compliance work. Different participants can use the same workspace with access suited to their responsibilities.
| Responsibility | Typical work |
|---|---|
| Leadership and programme sponsors | Set objectives, review priorities and decide where resources are needed. |
| Security and GRC teams | Maintain frameworks, coordinate assessments and follow risk responses. |
| Legal, compliance and privacy teams | Interpret applicable obligations and review the evidence supporting organisational decisions. |
| Business and information owners | Explain critical activities, information needs and the consequences of disruption. |
| System owners, architects and engineers | Describe the technical environment, implement controls and provide operational evidence. |
| Procurement and supplier managers | Maintain third-party context, dependencies and relationship reviews. |
| Risk analysts and assurance reviewers | Assess scenarios, challenge assumptions and review proposed decisions. |
| Auditors and control assessors | Plan reviews, examine evidence and record findings. |
| Policy readers and contributors | Consult relevant policies or contribute to selected work without broad administrative access. |
These are organisational responsibilities, not a promise that each name exists as a predefined workspace role. Use Settings → Roles to inspect the actual permission sets and Members to assign them.
Where a workflow requires separate analyst or assurance duties, configure those duties in the appropriate settings. Record ownership and explicit collaboration can also define who participates in individual records.
Start with the permissions required for the person's work. Review them when responsibilities change, and keep independent review separate from preparation where your governance model requires it.