IAM Accelerator Docs

Roles & Workflow

IAM Accelerator has one global role and three per-engagement roles. A single person can hold different engagement roles on different engagements — permissions are always evaluated per engagement, not per user account.

Roles

Role Scope Assign Can do
Firm Administrator (firm-admin) Global, cross-tenant Granted in Keycloak, not in-app The only role that can create/manage Clients and Engagements. Unrestricted read/write everywhere, including engagements they aren’t explicitly assigned to.
Assessor One engagement Engagement Team tab Uploads and links evidence, records/revises control ratings. The only role permitted to do either.
Reviewer One engagement Engagement Team tab Reviews an assessor’s work — approves/rejects evidence links, counted toward the “reviewer assigned” finalization check.
Client Viewer One engagement Engagement Team tab Read-only. Can only open the engagement once it’s Finalized or Archived — never earlier, so a client never sees an in-progress assessment.

Assigning or removing a user from an engagement never deletes history — removal just sets that assignment’s status to removed, so it can be reversed and the audit trail stays intact.

The engagement lifecycle

Every engagement moves through four statuses, strictly forward — there is no way to skip a status or move backward:

draft  →  in_progress  →  finalized  →  archived
Status What it means What’s locked
Draft Being scoped. Nothing yet — pillars and standard versions can still be changed.
In Progress Active assessment. Scope (pillars/standards) is now frozen. Requires at least one active assessor assigned before you can enter this status.
Finalized Assessment complete and signed off. Ratings can no longer be recorded or revised. A permanent score/gap snapshot is taken at this moment — later changes to scoring or weighting configuration never retroactively change a finalized engagement’s numbers. Client Viewers gain access from this point on.
Archived Closed out. Fully read-only, including the Roadmap (the one area still editable while Finalized).

Finalizing doesn’t require every box to be ticked — it surfaces non-blocking warnings instead, so you can finalize deliberately with known gaps in the record:

  • No reviewer assigned
  • Evidence links still pending review
  • Controls left unrated
  • Ratings flagged as needing revalidation
  • Incomplete gap analysis (open gaps missing business impact / effort)

End-to-end workflow

  1. Control Library — firm-wide reference data: Controls, Standards, Evidence Types, and the mappings between them. Not tied to any one client.
  2. Clients — create the tenant you’re assessing, and configure its report branding.
  3. Engagements — scope an assessment (pillars + standard versions) for a client and staff it via the Team tab.
  4. Evidence — assessors upload supporting evidence and link it to specific controls.
  5. Ratings — assessors rate each in-scope control’s current maturity (1–5), backed by evidence.
  6. Pillar Targets — set the desired maturity level per pillar for this engagement.
  7. Scores — weighted compliance scores are computed automatically from ratings.
  8. Gaps — the difference between current and target maturity, automatically prioritized.
  9. Roadmap — turn prioritized gaps into a remediation plan with owners and dates.
  10. Reports — generate branded executive or technical deliverables.
  11. Dashboard & Maturity Trend — track portfolio health and a client’s progress across assessment cycles.