How it plays out on a deal
In a data room, roles usually define what someone can do across the platform (invite users, change permissions, answer questions), while folder permissions define what they can see. Mixing the two up is a common source of setup mistakes.
A clear role model limits the number of people who can change permissions or invite outsiders. That matters for security reviews: a client may ask exactly how many people can alter access to a room, and the honest answer should be a short list, not everyone on the deal team.
What to check in a review or demo
- 1Which roles exist out of the box and whether custom roles can be defined.
- 2Whether the ability to invite outside users can be limited to a few named administrators.
- 3Whether role changes are logged with who made them and when.
Read alongside
- Permission groupsNamed sets of users, usually one per bidder or per adviser firm, that share the same access rights, so permissions are managed once per group instead of per person.
- Room administratorThe person, usually on the sell side or at the adviser, who builds the room, invites users, sets permissions and publishes documents.
- Principle of least privilegeThe security rule that each user should get only the access needed for their task, for only as long as they need it.
- Single sign-on (SSO)Logging in to the data room with an existing company identity, through a provider such as Microsoft Entra ID or Okta, usually over the SAML or OpenID Connect standards.