Skip to main content
Invariant uses role-based access with organization scoping. Key constraints:
  • Org scoping: every user is bound to one organization; data is isolated per org.
  • Roles: Administrator, QA Manager, and standard user roles determine what each person can view and do.
  • Controlled sign-offs (approve, close, effectiveness verification, reopen) are restricted to QA Manager / authorized approvers.
  • Maker-checker: an independent approver is required — authors cannot approve their own records.
  • Server-side enforcement: all access rules are enforced on the server, not just hidden in the UI.

Role boundaries for the updated workflows

Operators do not gain management access from this release. A feature being present in documentation or released software does not mean it is enabled for every organization or user.