Roles & Permissions
Galink uses a role-based access control system to manage what users can see and do within the platform.
Available roles
Admin
Full access to the entire platform, including Settings.
Can manage users, configure questionnaires, and access all features.
Regular
Access to all platform features except Settings.
Can manage vendors, conduct assessments, and review questionnaires.
Limited
Access to Home and Vendors pages only.
Vendor scope restriction: Limited users only see vendors where they are tagged (as Business Owner, Security Owner, or any custom user-type property).
Observer (Read-Only)
Read-only access to all sections except Settings and DORA.
Positioned between Limited and Disabled in the role hierarchy.
Cannot modify any data -- all inputs have a read-only appearance.
Observers are automatically redirected from restricted routes (e.g., /vendors/create redirects to /vendors).
Disabled
The user account is deactivated.
Cannot log in or access any platform features.
Disabled users do not need to be assigned to any organization.
Role hierarchy
From most to least privileged:
Admin > Regular > Limited > Observer > Disabled