Last updated: 2026-04-06
Guide
Available Roles & Permissions¶
Dxtra provides nine predefined roles for different team functions. Each role has specific permissions based on common responsibilities in privacy management.
Role Summary¶
| Role | Description | Access Level |
|---|---|---|
| Owner | Complete platform control including billing and user management | Full |
| Business Owner | Platform oversight with billing access | High |
| Admin | Day-to-day operations without billing access | High |
| Data Protection Officer | Compliance oversight and DPIAs | High |
| Data Controller | Define processing purposes and legal basis | Medium |
| Developer | Technical implementation and API access | Medium |
| Agency/Reseller | Multi-client management | Medium |
| Member | Basic operational access | Limited |
| Auditor/Regulator | Read-only compliance verification | Read-only |
Permission Matrix¶
Organization Management¶
| Feature | Owner | Business Owner | Admin | DPO | Data Controller | Developer | Agency | Member | Auditor |
|---|---|---|---|---|---|---|---|---|---|
| View organization | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Update organization | Yes | Yes | Yes | Yes | No | No | No | No | No |
| Delete organization | Yes | Yes | Yes | No | No | No | No | No | No |
| Manage users | Yes | Yes | Yes | No | No | No | No | No | No |
| Billing access | Yes | Yes | No | No | No | No | No | No | No |
Privacy Operations¶
| Feature | Owner | Business Owner | Admin | DPO | Data Controller | Developer | Agency | Member | Auditor |
|---|---|---|---|---|---|---|---|---|---|
| View data subjects | Yes | Yes | Yes | Yes | Yes | No | Yes | View | View |
| Manage data subjects | Yes | Yes | Yes | Yes | Yes | No | Yes | No | No |
| Processing activities | Yes | Yes | Yes | Yes | Yes | No | Yes | View | View |
| Privacy notices | Yes | Yes | Yes | Yes | Yes | No | Yes | View | View |
| Consent management | Yes | Yes | Yes | Yes | Yes | No | Yes | View | View |
Compliance & Reporting¶
| Feature | Owner | Business Owner | Admin | DPO | Data Controller | Developer | Agency | Member | Auditor |
|---|---|---|---|---|---|---|---|---|---|
| Compliance reports | Yes | Yes | Yes | Yes | Yes | No | Yes | View | Yes |
| DPIAs | Yes | Yes | Yes | Yes | Yes | No | Yes | No | View |
| Audit logs | Yes | Yes | Yes | Yes | View | No | Yes | View | Yes |
| Breach notifications | Yes | Yes | Yes | Yes | No | No | Yes | No | View |
Technical & Integration¶
| Feature | Owner | Business Owner | Admin | DPO | Data Controller | Developer | Agency | Member | Auditor |
|---|---|---|---|---|---|---|---|---|---|
| API keys | Yes | No | Yes | No | No | Yes | Yes | No | No |
| Integrations | Yes | Yes | Yes | No | No | Yes | Yes | View | View |
| Webhooks | Yes | No | Yes | No | No | Yes | Yes | No | No |
| File scanning | Yes | Yes | Yes | Yes | Yes | Yes | Yes | No | Yes |
Role Details¶
Owner¶
Complete platform authority with access to all features.
- Use for: CEO, Privacy Director, platform administrator
- Permissions: Everything including billing and user management
- Limit to: 1-2 individuals per organization
Business Owner¶
Strategic oversight with billing access.
- Use for: Business decision makers, executives
- Permissions: Billing, user management, privacy oversight
- Note: Similar to Owner but may have future feature restrictions
Admin¶
Day-to-day operational management.
- Use for: Privacy managers, operations leads
- Permissions: Most platform features except billing
- Note: Primary role for privacy team leads
Data Protection Officer¶
Specialized compliance role for designated DPOs.
- Use for: Designated DPO, compliance officers
- Permissions: Compliance operations, DPIAs, audit oversight
- Note: Aligns with GDPR Article 39 responsibilities
Data Controller¶
Legal authority for defining processing purposes.
- Use for: Legal representatives, processing decision makers
- Permissions: Processing activities, legal basis configuration
- Note: Read access to most compliance data
Developer¶
Technical implementation and integration access.
- Use for: Software developers, technical implementers
- Permissions: API keys, integrations, webhooks, file scanning
- Note: Limited privacy operations access
Agency/Reseller¶
Multi-client management for service providers.
- Use for: Privacy consultants, agencies, resellers
- Permissions: Client management, privacy operations
- Note: Access scoped to assigned clients only
Member¶
Basic operational access for team support.
- Use for: Privacy coordinators, junior staff
- Permissions: Read access to most data, limited write access
- Note: Default role for new team members
Auditor/Regulator¶
Read-only access for external compliance verification.
- Use for: External auditors, regulatory inspectors
- Permissions: Full read access to compliance documentation
- Note: Assign temporarily for audit duration only
Choosing a Role¶
| Situation | Recommended Role |
|---|---|
| New privacy team member | Member (upgrade if needed) |
| Privacy team lead | Admin |
| Technical integration work | Developer |
| Compliance audit | Auditor/Regulator |
| Designated DPO | Data Protection Officer |
| Executive oversight with billing | Business Owner |
| Full platform control | Owner |