Skip to content
Find my data room
Data room terms / Access and permissions

Role-based access control (RBAC)

The short version

An access model in which rights come from a user's role, such as administrator, contributor or viewer, rather than being granted to each person one by one.

How it plays out on a deal

In a data room, roles usually define what someone can do across the platform (invite users, change permissions, answer questions), while folder permissions define what they can see. Mixing the two up is a common source of setup mistakes.

A clear role model limits the number of people who can change permissions or invite outsiders. That matters for security reviews: a client may ask exactly how many people can alter access to a room, and the honest answer should be a short list, not everyone on the deal team.

What to check in a review or demo

  1. 1Which roles exist out of the box and whether custom roles can be defined.
  2. 2Whether the ability to invite outside users can be limited to a few named administrators.
  3. 3Whether role changes are logged with who made them and when.

Read alongside

Where this comes up on Data Room Review