1. Overview
Contract intELIEgence uses role-based access control (RBAC). Each user is assigned a role that determines what they can see and do within the platform. The platform defines 5 roles spanning three levels:
- Administrative — Admin (can also be assigned as Department Admin for specific departments)
- Operational — Super User, End User
- External — Customer, Supplier
2. Role Summary
| Role | Level | Access | Create / Edit | Approval |
|---|---|---|---|---|
| Admin | Administrative | Full access to all modules | Full create/edit everywhere | When assigned as Department Admin: approves/rejects contracts and CCRs for that department |
| Super User | Operational | Operational modules (excludes SLA & KPI — Admin-only) | Create contracts & CCRs; create/edit Suppliers (→ Pending); edit contracts only while Pending/Rejected | Contracts require approval by the department's Admin |
| End User | Operational | View access (Contracts, Analytics, Data Visualisation) | View-only on contracts; can raise CCRs | No approval capabilities |
| Customer | External | Own contracts only | Can raise CCRs; account auto-generated | No approval capabilities |
| Supplier | External | Own contracts and documents | Upload required documents (MOU, etc.); can raise CCRs | No approval capabilities |
3. Detailed Role Descriptions
3.1 Admin
- Full access to all Platform Config modules (Organisation, User Management, Notification, Connectors, Governance, Audit Logs)
- Full access to all Contract Hub modules
- Full access to all Tracking modules
- Full access to Analytics & Insights including Data Visualisation
- Creates and manages users, roles, catalogs, templates, and settings
- The Organisation signer email (set in Organisation → Settings) is the first e-signature signer — this is not tied to the Admin role, it's a configured email address
- Can override contract RAG status manually
- Can change contract status from the listing
- Can delete contracts
- Contract creation: status determined by dates (no approval needed)
Department Admin Responsibility
An Admin can be assigned as the Department Admin for one or more departments (configured in the Department module). When assigned, the Admin gains these additional capabilities for that department:
- Approves or rejects contracts created by Super Users in their department
- Approves or rejects CCRs for contracts in their department
- Receives review escalation notifications for their department's contracts
3.2 Super User
- Can create contracts — which enter Approval Pending for the Department Admin to approve or reject. A Super User can edit a contract only while it is Approval Pending or Rejected; once it is live, only an Admin can edit it
- Can create and edit Suppliers — a supplier added or edited by a Super User goes to Pending for Admin approval
- Can manage Service Manager, Contract Studio (templates & builder), Contract Capture, Notification templates, Governance, Cost Center, and the Performance Tracker & Cost Tracker
- Can assign SLAs to contracts (via the contract's SLA tab) and raise Contract Change Requests
- Cannot define standalone SLAs or KPIs — those modules are Admin-only
- Cannot delete or approve/reject contracts, and cannot access Organisation settings, User Management, Departments, Customers, or Audit Logs
3.3 End User
- View access to Contracts, Service Manager, Dashboards, Reports, System Calendar and Data Visualisation in their assigned scope
- Can raise Contract Change Requests and use the Ask CS assistant
- Read-only on contracts — cannot create or edit contract records
- No access to SLAs, KPIs, Suppliers, Customers, or Platform Config
- Useful for stakeholders who need visibility but should not modify data
3.4 Customer
- Account auto-created when a Customer record is saved (using Customer Email and Name)
- Logs in with provided credentials
- Views only their own contracts
- Can raise Contract Change Requests and use the Ask CS assistant
- Cannot create or edit contract records
- Receives e-signature requests for NDA signing (Invoice Profile flow)
3.5 Supplier
- Logs in to a self-service portal showing only their own profile and buy-side contracts
- Can edit their own profile and upload compliance documents (MOU, certificates, etc.) — uploaded documents go to Pending for an Admin to Accept or Reject
- Can raise Contract Change Requests and use the Ask CS assistant
- Receives e-signature requests for MOU signing
3.6 Custom Roles
Beyond the five built-in roles, an organisation administrator can create custom roles tailored to their team. In Organisation → Roles & Permissions:
- Create a role — give it a name and description.
- Assign permissions for each module → feature → tab, choosing from the actions View, Create, Edit, Delete and Approve (plus visibility).
- A custom role can only grant access to modules the organisation already has; mandatory modules and feature dependencies are enforced automatically.
Custom roles are then assignable to users in User Management, exactly like the built-in roles.
4. Role-Module Access Matrix
| Module Area | Admin | Super User | End User | Customer | Supplier |
|---|---|---|---|---|---|
| Platform Config Organisation, User Management, Audit Logs |
Full | — | — | — | — |
| SLA & KPI Admin-only configuration |
Full | — | — | — | — |
| Config & Trackers Notification, Connectors, Cost Center, Performance & Cost Tracker |
Full | Create/Edit | — | — | — |
| Governance | Full | Create/Edit | — | — | — |
| Contracts & Service Manager | Full + Approve/Reject as Dept Admin |
Create/Edit (approval required; edit only while Pending/Rejected) |
View | Own contracts | Own contracts |
| Customers & Departments | Full | — | — | — | — |
| Suppliers | Full | Create/Edit (→ Pending) |
— | — | Own profile |
| Contract Studio & Capture Templates, Builder, AI Capture |
Full | Create/Edit | — | — | — |
| Change Requests (CCR) | Full + Approve/Reject as Dept Admin |
Create | Create | Create | Create |
| Analytics Dashboard, Reports, Calendar |
Full | Full | View | — | — |
| Data Visualisation | Full | — | View | — | — |
| Document Signature | Full | View | View | — | — |
5. How Roles Affect Workflows
Contract Creation
Admin creates contracts directly — the status is set automatically based on start/end dates (no approval step required). Super User creates contracts that enter an Approval Pending state and must be approved by the Department Admin for the relevant department. While a contract is Approval Pending or Rejected, the Super User can still edit it; once it is approved and live, only an Admin can make further edits.
Contract Change Requests (CCR)
Both Admin and Super User can raise CCRs for value or date changes. The Department Admin for the contract's department reviews and approves or rejects the request.
Document Signing (e-Signature)
The Organisation's designated signer (email configured in Organisation → Settings) signs first. The external party (Customer or Supplier) signs second. Customers sign NDAs; Suppliers sign MOUs.
Contract Capture Sync
When a captured contract is synced, Admin creates the contract directly. Super User's synced contracts go through the standard department approval workflow.
Bulk Import
Available to both Admin and Super User roles. The same approval rules apply — Super User imports trigger approval workflows.
6. Tips
- Assign Department Admins carefully — they control the approval gate for contracts and CCRs in their department.
- Use End User for stakeholders who need visibility into contracts and data without the ability to edit or create records.
- Customer accounts are auto-created when a Customer record is saved — no manual user creation is needed.
- Suppliers can upload documents — leverage this for compliance tracking (MOU, certifications, etc.).