Roles and permissions in Evidence Hub

Evidence Hub uses role-based access control (RBAC) to decide who can discover, read, respond, review, archive, share, and delete each Evidence Record.

How Launchpad access maps to Evidence Hub roles

App-level role mapping uses Launchpad user type and subscription.

Launchpad user type Launchpad subscription Evidence Hub role Outcome
System Admin Professional, Results Lite Professional Evidence Admin Can manage governance settings. Discover does not automatically grant read or download access.
System Admin Contributor, Oversight, Results Lite Contributor, None Evidence Contributor Participates where assigned.
User Professional, Results Lite Professional Evidence Professional Can create records and act as owner.
User Contributor, Oversight, None Evidence Contributor Participates where assigned.

Note

Non-Diligent One users who authenticate with one-time passcode (OTP) are not part of Launchpad user type and subscription mapping. Their access is assignment-based at the Evidence Record level and is limited to the participation workflows granted to them.

 

How access is evaluated

On each request, the application evaluates two role-based control levels, applies permissions, and then enforces lifecycle and access-control limits.

  1. Application role determines baseline capability in the app, based on Launchpad user type and subscription.

  2. Record-level role determines role-specific actions for a specific Evidence Record.

  3. Permission set applies the following permissions: Discover, Read, Download, Respond, Define, Approve, Archive, Share, and Delete.

Permissions are additive. If more than one role applies, the user receives the combined permissions, subject to lifecycle limits and discoverability or downloadable control checks.

Application roles

Application roles define baseline capability across Evidence Hub.

Application role Minimum required role Core capability
Evidence Admin Evidence Professional Manages app governance, configuration, and oversight operations.
Evidence Professional Evidence Contributor Creates and manages Evidence Records, including ownership workflows.
Evidence Contributor Evidence Contributor Responds and reviews where assigned, and works with granted access.

Evidence Record-level roles

Record-level roles determine what users can do in a specific Evidence Record.

Evidence Record-level role Primary actions
Owner Creates requests, manages access, and accepts or rejects submissions.
Respondent / Alternate Respondent Provides response content, uploads files, and submits evidence.
Reviewer Reviews submissions and decides outcomes in the review stage.
Viewer Has read-only visibility into record content and activity.

Discoverability controls

Discoverability determines who can find a record in list and search views.

Discoverable evidence

Discoverability is resolved through record-level and label-level configuration. When a record is marked discoverable through record-level or label-level configuration, Evidence Admin, Evidence Professional, and Evidence Contributor are able to find the record in search and list views.

Non-discoverable evidence

When a record is marked non-discoverable through record-level or label-level configuration, access is tightly limited.

  • The Evidence Owner can always open the record.

  • An Evidence Admin can list and discover every record, including non-discoverable ones, through admin override. Reading a record still requires ownership or granted access, otherwise the admin sees an Access denied message.

  • Evidence Professionals and Evidence Contributors are able to view all discoverable records they have been granted access to. For a discoverable record they cannot yet open, they submit an access request to view its details.

Download controls

Download access is evaluated separately from discover and read access. A user can download attachments only when all the following required checks pass:

  • Read access to the record

  • The record's Downloadable setting allows downloads

  • Any required downloadable label-based access is satisfied

How discover and download are resolved

Discoverable access determines whether a user can find and open a record. Downloadable access determines whether that user can download file attachments from the record.

  • Discoverable match without downloadable match: the user can discover and read, but cannot download.

  • Discoverable and downloadable match: the user can discover, read, and download.

  • No discoverable match: the record is not visible unless direct assignment applies.

Permissions and status limits

Some permissions are always available when granted, while others depend on record lifecycle status.

Permission What it allows
Discover Find a record and view metadata according to access.
Read Open the full record, including criteria, files, comments, and activity.
Download Download record attachments when download controls allow it.
Respond Edit response content, upload or remove files, and add comments. Available before Awaiting Review.
Define Update criteria, instructions, and labels. Available before Awaiting Review.
Approve Accept or reject submitted evidence. Available only in Awaiting Review.
Archive Move a record to the archive state.
Share Manage assignments, links, and discoverability settings.
Delete Permanently remove a record. State-based limits apply.

Role and permission matrix for Evidence Record

This matrix shows baseline permission outcomes by role. Label and record settings can further restrict discover and download access when direct assignment does not apply.

Permission Evidence Admin (no record role) Owner Respondent / Alternate Respondent Reviewer Viewer
Discover Always Yes Yes Yes Yes
Read No Yes Yes Yes Yes
Download No Yes Yes* Yes* Yes*
Respond No Yes Yes No No
Define No Yes No No No
Approve No Yes No Yes No
Archive Yes Yes No No No
Share Bulk owner reassignment only Yes No No No
Delete Archived accepted, or not accepted records Records that are not accepted No No No

* When Downloadable flag in Evidence Record-level configuration and label-level downloadability restriction is enabled or the user is added to an Exempt launchpad group.

Note

Evidence Admin permissions in this matrix reflect governance override. An Evidence Admin can discover any record and archive or delete records where lifecycle policy allows. However, accepted and active records cannot be deleted by anyone, while accepted archived records can be deleted only by an Evidence Admin. An Evidence Admin cannot read or download evidence without first granting record access, and the record activity log captures this self-grant.

How label and record settings affect access

When direct role-based access does not apply, label and record settings resolve discover and download outcomes.

  • Direct assignment wins Assigned owner, respondent, alternate respondent, reviewer, viewer, or approved requester access is not removed by label restrictions.

  • Admin discover override Evidence Admins can discover all records, including non-discoverable records, but read and download still require record access.

  • Label restrictions take precedence For non-assigned users, discoverable and downloadable label rules override record toggles.