Roles & Workflow
IAM Accelerator has one global role and three per-engagement roles. A single person can hold different engagement roles on different engagements — permissions are always evaluated per engagement, not per user account.
Roles
| Role | Scope | Assign | Can do |
|---|---|---|---|
Firm Administrator (firm-admin) |
Global, cross-tenant | Granted in Keycloak, not in-app | The only role that can create/manage Clients and Engagements. Unrestricted read/write everywhere, including engagements they aren’t explicitly assigned to. |
| Assessor | One engagement | Engagement Team tab | Uploads and links evidence, records/revises control ratings. The only role permitted to do either. |
| Reviewer | One engagement | Engagement Team tab | Reviews an assessor’s work — approves/rejects evidence links, counted toward the “reviewer assigned” finalization check. |
| Client Viewer | One engagement | Engagement Team tab | Read-only. Can only open the engagement once it’s Finalized or Archived — never earlier, so a client never sees an in-progress assessment. |
Assigning or removing a user from an engagement never deletes history — removal just sets that assignment’s status to
removed, so it can be reversed and the audit trail stays intact.
The engagement lifecycle
Every engagement moves through four statuses, strictly forward — there is no way to skip a status or move backward:
draft → in_progress → finalized → archived
| Status | What it means | What’s locked |
|---|---|---|
| Draft | Being scoped. | Nothing yet — pillars and standard versions can still be changed. |
| In Progress | Active assessment. | Scope (pillars/standards) is now frozen. Requires at least one active assessor assigned before you can enter this status. |
| Finalized | Assessment complete and signed off. | Ratings can no longer be recorded or revised. A permanent score/gap snapshot is taken at this moment — later changes to scoring or weighting configuration never retroactively change a finalized engagement’s numbers. Client Viewers gain access from this point on. |
| Archived | Closed out. | Fully read-only, including the Roadmap (the one area still editable while Finalized). |
Finalizing doesn’t require every box to be ticked — it surfaces non-blocking warnings instead, so you can finalize deliberately with known gaps in the record:
- No reviewer assigned
- Evidence links still pending review
- Controls left unrated
- Ratings flagged as needing revalidation
- Incomplete gap analysis (open gaps missing business impact / effort)
End-to-end workflow
- Control Library — firm-wide reference data: Controls, Standards, Evidence Types, and the mappings between them. Not tied to any one client.
- Clients — create the tenant you’re assessing, and configure its report branding.
- Engagements — scope an assessment (pillars + standard versions) for a client and staff it via the Team tab.
- Evidence — assessors upload supporting evidence and link it to specific controls.
- Ratings — assessors rate each in-scope control’s current maturity (1–5), backed by evidence.
- Pillar Targets — set the desired maturity level per pillar for this engagement.
- Scores — weighted compliance scores are computed automatically from ratings.
- Gaps — the difference between current and target maturity, automatically prioritized.
- Roadmap — turn prioritized gaps into a remediation plan with owners and dates.
- Reports — generate branded executive or technical deliverables.
- Dashboard & Maturity Trend — track portfolio health and a client’s progress across assessment cycles.