Define who prepares assessments, owns risks, approves decisions and verifies the result. Use named people or accountable teams, with suitable separation between preparation and independent review where your governance model requires it.

Distinguish the responsibilities

ResponsibilityExpected contribution
Programme sponsor or security leadEstablish direction, resources and escalation authority.
GRC or risk managerCoordinate the process and maintain assessment consistency.
Business or risk ownerExplain the business consequences and remain accountable for the risk decision.
AnalystEvaluate scenarios, assumptions, likelihood, impact and response options.
Assurance reviewer or auditorChallenge the basis of a conclusion and review supporting evidence.
System or third-party ownerMaintain operational context and coordinate the relevant changes.
Policy or control ownerMaintain requirements, implementation information and review evidence.
Remediation ownerDeliver and report the agreed response work.

These responsibilities may be combined in a small organisation or distributed across several teams. Document conflicts of interest and the review arrangements used to address them.

Configure application access

Open Settings → Roles to inspect the available permission sets or create custom roles. Use Settings → Members to assign the required roles to each participant.

A job title is not an access grant. Likewise, an application permission does not confer organisational authority to accept a risk or approve spending. Record that authority through the programme's governance arrangements.

Configure workflow duties

In Settings → Risk demands, select the roles used for analyst and assurance review and decide whether the gate requires one or all eligible reviewers. Use Approvals for the supported framework and policy approval workflows.

Check that the selected roles have suitable active members and the access needed to perform the review. A mandatory gate without an eligible reviewer can stop work from progressing.

Record ownership and explicit collaboration can define participation in individual items. Review these assignments when people leave, change jobs or transfer responsibility. A current role list and an old record owner can otherwise tell conflicting stories about who should act.