DocumentationRoles and administration
Browse the guides
CAIRN

Pilot guide · 6 September 2026

Start here

Roles and administration

Understand ownership, customer permissions and approval responsibilities.

Draft for the planned pilot release. These pages describe the intended customer experience. Administration and hosted-service features are not yet released; no live product URL or support service is claimed.

Your organisation's members have named accounts and specific permissions.

RoleIntended purpose
Customer ownerManage organisational ownership and administrators
AdministratorManage members, agents and configuration within the organisation
Policy approverIndependently approve a proposed policy change
Action approverReview an exact held action within an assigned scope
OperatorRun permitted workflows and inspect permitted sessions
Auditor/viewerInspect authorised evidence without changing controls

A person may be assigned more than one role where the organisation allows it. They must not approve their own requested action or policy change. Being an administrator does not grant access to another customer.

The customer administration area must support invitations, role changes, removal of access, connector revocation and transfer of ownership. Removing a user ends their active access while preserving historical attribution of their actions.

Cairn staff have separate operational roles. Any support access to customer content must have a stated purpose, scope, expiry and audit record.

This permission model is a release requirement; the current prototype console does not implement authenticated user administration.

CAIRN INTEGRITYCustomer documentation draft