Skip to content
Last updated: 2026-04-06
Guide

Role & Permission Management

Dxtra uses predefined roles rather than custom permissions. This approach ensures consistent security and simplifies compliance.

Available Roles

Category Roles
Leadership Owner, Business Owner, Data Protection Officer, Data Controller
Operations Admin, Agency/Reseller
Team Developer, Member
External Auditor/Regulator

See Available Roles & Permissions for detailed permission information.

Assigning Roles

New Users

  1. Navigate to Settings > Users & Roles
  2. Click Invite User
  3. Enter email address
  4. Select role from dropdown
  5. Click Send Invitation

The user receives an email with setup instructions. After creating their account, they have access based on the assigned role.

Existing Users

  1. Go to Settings > Users & Roles
  2. Find the user in the list
  3. Click to edit
  4. Change role selection
  5. Save changes

Role changes take effect immediately.

Role Selection Guidelines

Start with Minimum Access

User Type Start With Upgrade To
New team member Member Admin when needed
External consultant Member Agency/Reseller for multi-client
Technical staff Developer Admin if managing non-technical tasks
Auditor Auditor/Regulator Never (remove after audit)

When to Change Roles

Change a role when:

  • User responsibilities change significantly
  • User needs features unavailable in their current role
  • Security review identifies over-privileged access
  • User transitions to different team function

Role Change Process

  1. Verify the user actually needs additional access
  2. Select role with minimum necessary permissions
  3. Update in user management interface
  4. Document reason for change
  5. Review usage after 30 days

Troubleshooting

User Cannot Access a Feature

  1. Check assigned role in Settings > Users & Roles
  2. Verify role includes required permission (see permission matrix)
  3. If legitimate need, upgrade to appropriate role
  4. Confirm account is active (not disabled)

User Has Excessive Access

  1. Review current role assignment
  2. Determine minimum required permissions
  3. Downgrade to appropriate role
  4. Communicate change to user

Invitation Not Received

  1. Check spam/junk folder
  2. Verify email address is correct
  3. Resend invitation from user management
  4. Invitations expire after 7 days

Best Practices

  • Quarterly Reviews: Audit all user roles
  • Document Changes: Record role assignment reasons
  • Immediate Removal: Remove access when users leave
  • Temporary Access: Use time-limited access for auditors and consultants