Define who prepares assessments, owns risks, approves decisions and verifies the result. Use named people or accountable teams, with suitable separation between preparation and independent review where your governance model requires it.
Distinguish the responsibilities
| Responsibility | Expected contribution |
|---|---|
| Programme sponsor or security lead | Establish direction, resources and escalation authority. |
| GRC or risk manager | Coordinate the process and maintain assessment consistency. |
| Business or risk owner | Explain the business consequences and remain accountable for the risk decision. |
| Analyst | Evaluate scenarios, assumptions, likelihood, impact and response options. |
| Assurance reviewer or auditor | Challenge the basis of a conclusion and review supporting evidence. |
| System or third-party owner | Maintain operational context and coordinate the relevant changes. |
| Policy or control owner | Maintain requirements, implementation information and review evidence. |
| Remediation owner | Deliver and report the agreed response work. |
These responsibilities may be combined in a small organisation or distributed across several teams. Document conflicts of interest and the review arrangements used to address them.
Configure application access
Open Settings → Roles to inspect the available permission sets or create custom roles. Use Settings → Members to assign the required roles to each participant.
A job title is not an access grant. Likewise, an application permission does not confer organisational authority to accept a risk or approve spending. Record that authority through the programme's governance arrangements.
Configure workflow duties
In Settings → Risk demands, select the roles used for analyst and assurance review and decide whether the gate requires one or all eligible reviewers. Use Approvals for the supported framework and policy approval workflows.
Check that the selected roles have suitable active members and the access needed to perform the review. A mandatory gate without an eligible reviewer can stop work from progressing.
Record ownership and explicit collaboration can define participation in individual items. Review these assignments when people leave, change jobs or transfer responsibility. A current role list and an old record owner can otherwise tell conflicting stories about who should act.