Team, invitations and application roles

Invite your colleagues, assign the right application roles (administrator, contributor, reader), and understand the separation between application role and legal role (Privacy Officer / RPRP).

2 min read

Inviting a colleague

From Settings > Team, click Invite a member. Enter their work email and choose their application role (see next section). Conformaze automatically sends an invitation email containing a secure link valid for 7 days. The member creates their password (12 characters minimum, no common patterns) and activates their access. Multi-factor authentication (MFA) is strongly recommended: it can be made mandatory for the entire team from Settings > Security.

Available application roles

Four application roles are available. Administrator: full access, manages the team, billing, and settings; can approve ROPA registers. Contributor: writes and edits activities, PIAs, incidents, and other documents; can submit for approval but not approve. Reader: read-only access, useful for executives or one-off external auditors. Application Privacy Officer: equivalent to a contributor, plus the right to approve PIAs, DPA contracts, and incident notifications — this is the technical translation of the legal Privacy Officer role.

Application role vs legal role

Be careful not to confuse these. The application role (Administrator, Contributor, Reader, Application Privacy Officer) controls what a person can do inside Conformaze. The legal role (official RPRP / Privacy Officer of the organization, designated executive) is a responsibility designated by management and mentioned in your official exports — it is set in Settings > Legal Roles. The same person can hold both the legal RPRP role and the application Privacy Officer role, but it is not required: for example, an external Privacy Officer (law firm) can be appointed legally without having direct access to the platform.

Tip

Designate at least two administrators in your organization. If the only administrator becomes unavailable or leaves, you may temporarily lose control of invitations and billing.

Modifying or revoking access

From Settings > Team, click on a member to change their role or disable their access. Disabling is immediate: the member's active session is invalidated. All actions already performed by this member remain in the audit trail with their identity — disabling never erases history. For a permanent departure, use Remove member after documenting the reason; this action is itself tracked.

Security and best practices

A few recommendations to protect your workspace: (1) Enable multi-factor authentication (MFA) for the entire team — it is the single measure that blocks most phishing attacks. (2) Reduce roles to the minimum needed (least-privilege principle): not everyone needs to be an Administrator. (3) Review the team list at least once per quarter to detect stale access. (4) For one-off access by external auditors, use the Reader role and disable it as soon as the engagement ends.

    Team, invitations and application roles — Conformaze Help Center | Conformaze