> ## Documentation Index
> Fetch the complete documentation index at: https://docs.elevatedsignals.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Roles & permissions

> Role model and what each role can do.

Invariant uses role-based access with organization scoping. Key constraints:

* **Org scoping:** every user is bound to one organization; data is isolated per org.
* **Roles:** Administrator, QA Manager, and standard user roles determine what each person can view and do.
* **Controlled sign-offs** (approve, close, effectiveness verification, reopen) are restricted to QA Manager / authorized approvers.
* **Maker-checker:** an independent approver is required — authors cannot approve their own records.
* **Server-side enforcement:** all access rules are enforced on the server, not just hidden in the UI.

## Role boundaries for the updated workflows

| Workflow                             | Role and availability boundary                                                         |
| ------------------------------------ | -------------------------------------------------------------------------------------- |
| CSV validation and imports           | Administrator; onboarding imports enabled. User imports need their additional feature. |
| Filter the training matrix           | Administrator, QA manager, or reviewer; employee-group training enabled.               |
| Create or retire curriculum versions | Administrator or QA manager; employee-group training enabled.                          |
| List or download operational reports | Administrator or QA manager, with applicable reporting availability.                   |
| Maintain document categories         | Administrator; document categories enabled.                                            |
| Open an audit-linked record          | The destination retains its organization, role, and feature checks.                    |

Operators do not gain management access from this release. A feature being present in documentation
or released software does not mean it is enabled for every organization or user.
