Team roles
Role-based guidance for admins, compliance owners, auditors, and vendors using Stackflo.
Team roles
Stackflo supports different users with clear responsibilities, permissions, and workflows.
Admin / Program Owner
Admins set up the organization, manage permissions, and maintain the overall compliance program.
Key responsibilities:
- Configure organization details and security settings.
- Assign team members to policies, controls, and audits.
- Manage framework subscriptions and tool integrations.
- Review compliance dashboards and readiness signals.
Compliance / GRC Owner
Compliance owners track policies, controls, evidence, and audit readiness.
Key responsibilities:
- Create and maintain governance policies.
- Map controls to compliance frameworks.
- Monitor evidence collection and control status.
- Drive remediation for gaps and audit findings.
Security / Controls Owner
Security leads own control implementation, evidence, and risk mitigation.
Key responsibilities:
- Review and update control details.
- Attach evidence to controls and confirm completion.
- Support policy requirements with documented proof.
- Monitor non-compliance and act on control exceptions.
Auditor
Auditors review evidence, verify compliance, and assess audit readiness.
Key responsibilities:
- Access audit timelines and active audit tasks.
- Review evidence, findings, and remediation status.
- Confirm control mappings to standards.
- Track completed and pending audit activities.
Vendor / Third-party Partner
Vendors use a separate portal to respond to compliance requests and share evidence.
Key responsibilities:
- Complete assessment questions.
- Upload certificates, policies, and compliance documents.
- Track open requests and submission status.
- Provide evidence for vendor risk assessments.
Policy portal user
Policy portal users access published policies, training information, and approval workflows.
Key responsibilities:
- Read published policies and understand expectations.
- Track policy changes and version updates.
- Confirm compliance with internal governance.
How teams work together
Stackflo connects these roles through shared workflows:
- Admins and compliance owners build the program.
- Security owners map controls and provide evidence.
- Auditors validate readiness and findings.
- Vendors contribute third-party evidence.
- Policy portal users stay informed on governance and expectations.
