Roles and permissions in Evidence Hub
Evidence Hub uses role-based access control (RBAC) to decide who can discover, read, respond, review, archive, share, and delete each Evidence Record.
How Launchpad access maps to Evidence Hub roles
App-level role mapping uses Launchpad user type and subscription.
| Launchpad user type | Launchpad subscription | Evidence Hub role | Outcome |
|---|---|---|---|
| System Admin | Professional, Results Lite Professional | Evidence Admin | Can manage governance settings. Discover does not automatically grant read or download access. |
| System Admin | Contributor, Oversight, Results Lite Contributor, None | Evidence Contributor | Participates where assigned. |
| User | Professional, Results Lite Professional | Evidence Professional | Can create records and act as owner. |
| User | Contributor, Oversight, None | Evidence Contributor | Participates where assigned. |
Note
Non-Diligent One users who authenticate with one-time passcode (OTP) are not part of Launchpad user type and subscription mapping. Their access is assignment-based at the Evidence Record level and is limited to the participation workflows granted to them.
How access is evaluated
On each request, the application evaluates two role-based control levels, applies permissions, and then enforces lifecycle and access-control limits.
-
Application role determines baseline capability in the app, based on Launchpad user type and subscription.
-
Record-level role determines role-specific actions for a specific Evidence Record.
-
Permission set applies the following permissions: Discover, Read, Download, Respond, Define, Approve, Archive, Share, and Delete.
Permissions are additive. If more than one role applies, the user receives the combined permissions, subject to lifecycle limits and discoverability or downloadable control checks.
Application roles
Application roles define baseline capability across Evidence Hub.
| Application role | Minimum required role | Core capability |
|---|---|---|
| Evidence Admin | Evidence Professional | Manages app governance, configuration, and oversight operations. |
| Evidence Professional | Evidence Contributor | Creates and manages Evidence Records, including ownership workflows. |
| Evidence Contributor | Evidence Contributor | Responds and reviews where assigned, and works with granted access. |
Evidence Record-level roles
Record-level roles determine what users can do in a specific Evidence Record.
| Evidence Record-level role | Primary actions |
|---|---|
| Owner | Creates requests, manages access, and accepts or rejects submissions. |
| Respondent / Alternate Respondent | Provides response content, uploads files, and submits evidence. |
| Reviewer | Reviews submissions and decides outcomes in the review stage. |
| Viewer | Has read-only visibility into record content and activity. |
Discoverability controls
Discoverability determines who can find a record in list and search views.
Discoverable evidence
Discoverability is resolved through record-level and label-level configuration. When a record is marked discoverable through record-level or label-level configuration, Evidence Admin, Evidence Professional, and Evidence Contributor are able to find the record in search and list views.
Non-discoverable evidence
When a record is marked non-discoverable through record-level or label-level configuration, access is tightly limited.
-
The Evidence Owner can always open the record.
-
An Evidence Admin can list and discover every record, including non-discoverable ones, through admin override. Reading a record still requires ownership or granted access, otherwise the admin sees an Access denied message.
-
Evidence Professionals and Evidence Contributors are able to view all discoverable records they have been granted access to. For a discoverable record they cannot yet open, they submit an access request to view its details.
Download controls
Download access is evaluated separately from discover and read access. A user can download attachments only when all the following required checks pass:
-
Read access to the record
-
The record's Downloadable setting allows downloads
-
Any required downloadable label-based access is satisfied
How discover and download are resolved
Discoverable access determines whether a user can find and open a record. Downloadable access determines whether that user can download file attachments from the record.
-
Discoverable match without downloadable match: the user can discover and read, but cannot download.
-
Discoverable and downloadable match: the user can discover, read, and download.
-
No discoverable match: the record is not visible unless direct assignment applies.
Permissions and status limits
Some permissions are always available when granted, while others depend on record lifecycle status.
| Permission | What it allows |
|---|---|
| Discover | Find a record and view metadata according to access. |
| Read | Open the full record, including criteria, files, comments, and activity. |
| Download | Download record attachments when download controls allow it. |
| Respond | Edit response content, upload or remove files, and add comments. Available before Awaiting Review. |
| Define | Update criteria, instructions, and labels. Available before Awaiting Review. |
| Approve | Accept or reject submitted evidence. Available only in Awaiting Review. |
| Archive | Move a record to the archive state. |
| Share | Manage assignments, links, and discoverability settings. |
| Delete | Permanently remove a record. State-based limits apply. |
Role and permission matrix for Evidence Record
This matrix shows baseline permission outcomes by role. Label and record settings can further restrict discover and download access when direct assignment does not apply.
| Permission | Evidence Admin (no record role) | Owner | Respondent / Alternate Respondent | Reviewer | Viewer |
|---|---|---|---|---|---|
| Discover | Always | Yes | Yes | Yes | Yes |
| Read | No | Yes | Yes | Yes | Yes |
| Download | No | Yes | Yes* | Yes* | Yes* |
| Respond | No | Yes | Yes | No | No |
| Define | No | Yes | No | No | No |
| Approve | No | Yes | No | Yes | No |
| Archive | Yes | Yes | No | No | No |
| Share | Bulk owner reassignment only | Yes | No | No | No |
| Delete | Archived accepted, or not accepted records | Records that are not accepted | No | No | No |
* When Downloadable flag in Evidence Record-level configuration and label-level downloadability restriction is enabled or the user is added to an Exempt launchpad group.
Note
Evidence Admin permissions in this matrix reflect governance override. An Evidence Admin can discover any record and archive or delete records where lifecycle policy allows. However, accepted and active records cannot be deleted by anyone, while accepted archived records can be deleted only by an Evidence Admin. An Evidence Admin cannot read or download evidence without first granting record access, and the record activity log captures this self-grant.
How label and record settings affect access
When direct role-based access does not apply, label and record settings resolve discover and download outcomes.
-
Direct assignment wins Assigned owner, respondent, alternate respondent, reviewer, viewer, or approved requester access is not removed by label restrictions.
-
Admin discover override Evidence Admins can discover all records, including non-discoverable records, but read and download still require record access.
-
Label restrictions take precedence For non-assigned users, discoverable and downloadable label rules override record toggles.