CSFaaS supports the people who direct, perform and review cybersecurity governance, risk and compliance work. Different participants can use the same workspace with access suited to their responsibilities.

ResponsibilityTypical work
Leadership and programme sponsorsSet objectives, review priorities and decide where resources are needed.
Security and GRC teamsMaintain frameworks, coordinate assessments and follow risk responses.
Legal, compliance and privacy teamsInterpret applicable obligations and review the evidence supporting organisational decisions.
Business and information ownersExplain critical activities, information needs and the consequences of disruption.
System owners, architects and engineersDescribe the technical environment, implement controls and provide operational evidence.
Procurement and supplier managersMaintain third-party context, dependencies and relationship reviews.
Risk analysts and assurance reviewersAssess scenarios, challenge assumptions and review proposed decisions.
Auditors and control assessorsPlan reviews, examine evidence and record findings.
Policy readers and contributorsConsult relevant policies or contribute to selected work without broad administrative access.

These are organisational responsibilities, not a promise that each name exists as a predefined workspace role. Use Settings → Roles to inspect the actual permission sets and Members to assign them.

Where a workflow requires separate analyst or assurance duties, configure those duties in the appropriate settings. Record ownership and explicit collaboration can also define who participates in individual records.

Start with the permissions required for the person's work. Review them when responsibilities change, and keep independent review separate from preparation where your governance model requires it.