Stakflo

Product documentation

Stakflo

Team roles

Role-based guidance for admins, compliance owners, auditors, and vendors using Stackflo.

Team roles

Stackflo supports different users with clear responsibilities, permissions, and workflows.

Admin / Program Owner

Admins set up the organization, manage permissions, and maintain the overall compliance program.

Key responsibilities:

  • Configure organization details and security settings.
  • Assign team members to policies, controls, and audits.
  • Manage framework subscriptions and tool integrations.
  • Review compliance dashboards and readiness signals.

Compliance / GRC Owner

Compliance owners track policies, controls, evidence, and audit readiness.

Key responsibilities:

  • Create and maintain governance policies.
  • Map controls to compliance frameworks.
  • Monitor evidence collection and control status.
  • Drive remediation for gaps and audit findings.

Security / Controls Owner

Security leads own control implementation, evidence, and risk mitigation.

Key responsibilities:

  • Review and update control details.
  • Attach evidence to controls and confirm completion.
  • Support policy requirements with documented proof.
  • Monitor non-compliance and act on control exceptions.

Auditor

Auditors review evidence, verify compliance, and assess audit readiness.

Key responsibilities:

  • Access audit timelines and active audit tasks.
  • Review evidence, findings, and remediation status.
  • Confirm control mappings to standards.
  • Track completed and pending audit activities.

Vendor / Third-party Partner

Vendors use a separate portal to respond to compliance requests and share evidence.

Key responsibilities:

  • Complete assessment questions.
  • Upload certificates, policies, and compliance documents.
  • Track open requests and submission status.
  • Provide evidence for vendor risk assessments.

Policy portal user

Policy portal users access published policies, training information, and approval workflows.

Key responsibilities:

  • Read published policies and understand expectations.
  • Track policy changes and version updates.
  • Confirm compliance with internal governance.

How teams work together

Stackflo connects these roles through shared workflows:

  • Admins and compliance owners build the program.
  • Security owners map controls and provide evidence.
  • Auditors validate readiness and findings.
  • Vendors contribute third-party evidence.
  • Policy portal users stay informed on governance and expectations.