Roles & Permissions
Access in qportal is controlled by seven roles, assigned to users by your administrator (see Tenant Setup & Subscription). A user can hold more than one role at the same time — for example, an Audit Manager who also administers master data.
The seven roles
Section titled “The seven roles”| Role | Typical user |
|---|---|
| Audit Manager | Plans audits and programs, owns the audit lifecycle, oversees action items |
| Auditor | Conducts audits, records findings |
| Auditee | Responds to findings assigned to their area, completes action items |
| Master Data Admin | Maintains reference data used across all modules |
| Master Data Viewer | Read-only access to master data; included automatically with every other role |
| Root Cause Contributor | Works on root cause analyses they created or are a team member of |
| Root Cause Manager | Works on every root cause analysis and approves or rejects them |
What each role can do, by module
Section titled “What each role can do, by module”| Module | Audit Manager | Auditor | Auditee | Master Data Admin |
|---|---|---|---|---|
| Audit Programs | Create, plan, release, cancel | Read | No access | Read |
| Audits | Create, plan, start, complete, publish findings, reopen, cancel; manage the audit team; direct edits at any lifecycle stage | Conduct fieldwork, document findings; direct edits only while an audit is In Progress (see Audit Lifecycle) | Read own assigned audits | Read |
| Question Catalogs | Create, edit, version | Read | No access | Read |
| Findings | Full edit, including status transitions | Full edit, including status transitions | Read findings (and the underlying question response) for audits against their own org unit, once findings are published | Read |
| Action Items — Action Workbench | Full edit, comments, effectiveness review, close/cancel | Full edit, comments, effectiveness review, close/cancel | No access | Read |
| Action Items — My Actions | Own assigned items | Own assigned items | Start, complete, reopen own assigned items; add comments | No access |
| Master Data | Read | Read | No access | Create, edit, archive |
Auditees see the audits and action items they are personally involved in — either as a team member or as the responsible person on an action item — plus findings (and the question responses behind them) for any audit against their own org unit, once that audit’s findings have been published. They have read-only access to the Findings Overview under those conditions, but do not have access to the Action Workbench.
Root Cause Analysis
Section titled “Root Cause Analysis”The Root Cause Analysis module has two roles of its own, because problem-solving teams are usually staffed differently from audit teams — production, purchasing or supplier management people who have no business in the audit apps:
| Root Cause Contributor | Root Cause Manager | |
|---|---|---|
| See analyses | Own analyses and those they are a team member of | All analyses |
| Create and edit | Yes, within that scope | Yes, unrestricted |
| Start, submit for verification | Yes | Yes |
| Approve / reject | No | Yes — exclusively |
The split exists so that nobody signs off their own work: the team that investigated a problem submits it, and a Root Cause Manager confirms that the causes are plausible and the measures worked. See Analysis Lifecycle.
Whether these roles appear at all depends on your subscription — Root Cause Analysis is licensed as a separate module, see Tenant Setup & Subscription.
- Master Data Viewer is not assigned on its own — it is bundled with every other role so that all users can look up reference values (e.g. org units, rating options) even if they can’t edit them.
- Role assignment happens outside of qportal, in the SAP BTP Cockpit. See Tenant Setup & Subscription for how your administrator assigns roles to users.