Share this article

Introducing expanded Role-Based Access Control
Accelerating security solutions for small businesses Tagore offers strategic services to small businesses. | A partnership that can scale Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. | Standing out from competitors Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. |
Today we’re thrilled to announce that Vanta’s Role-Based Access Control (RBAC) functionality has gotten even stronger with new capabilities, including:
- Additional pre-built roles now available in Vanta
- The ability to create custom roles, each with their own access and permission rights.
These expanded RBAC capabilities are now generally available and demonstrate Vanta’s continued commitment to supporting the needs of larger, more advanced organizations through additional customization and flexibility across our platform.
What is Role-Based Access Control?
Role-Based Access Control is control over user groups and access to resources based on a defined role. In software applications, it’s important to ensure that users have the appropriate permissions and can only view data or perform actions required for their role, consistent with the “principle of least privilege.” RBAC is especially important for applications that contain or connect to sensitive data and in cases where multiple teams and employees need different levels of access to software. And for larger, maturing organizations, flexible RBAC functionality is typically a requirement for compliance, risk, or cybersecurity applications.
Vanta previously came with three pre-built roles — Admins, Editors and Employees. This met the needs of most customers. but some needed additional flexibility and role customization.
Expanded RBAC in Vanta
With Vanta’s expanded RBAC capabilities, customers now have this additional flexibility and customization. The new functionality includes:
Two additional pre-built roles aimed at specific user types
View-only Administrator role: This role gives view-only access to everything in Vanta. Since View-only Administrators do not have the ability to edit or change any configurations, this role is appropriate for users (such as senior security or compliance executive) who need to be able to view information in Vanta but aren’t involved in any configuration or administrative changes.
Sales Administrator role: This role can view basic information and manage external access to an organization's public Trust Report powered by Vanta. This role is appropriate for sales team members who are working with prospects evaluating their offering. If a prospect requests a sensitive compliance document through a Trust Report, Sales Administrators can approve the request or deny access if the requester is unknown.
These additional pre-built roles are now available in Vanta to all customers at no additional cost. Stay tuned for more pre-built roles in the coming months.

Custom roles
Vanta now lets you create an unlimited number of custom roles, each with their own granular view and edit permissions to all areas of the Vanta interface. This flexibility is especially important for larger organizations with many teams and employees requiring different levels of access to Vanta.
For example, you can create a “Vendor security review” role for users that only need access to the Vendors tab to perform security and risk reviews of third-party vendors. For team members in your Legal department, you might create a “Legal” role that can only view and edit policies in Vanta.
Custom role creation is now available to Vanta customers at an additional cost. To learn more about pricing, please reach out to your account executive or contact us here.

Permission details page
Last but not least, Vanta’s new ”Permission details” page gives Administrators a bird’s-eye view of the different view, edit, and no access permission levels across pre-built and custom roles. This makes it easy for Administrators to quickly get an understanding of the various roles they have in Vanta or where they might need to make adjustments.

Get started with expanded RBAC in Vanta
Current customers can now access the new pre-built roles in Vanta here. If you’re interested in learning more about custom roles or additional customization capabilities, reach out to your account executive or customer success manager or contact us here.





FEATURED VANTA RESOURCE
The ultimate guide to scaling your compliance program
Learn how to scale, manage, and optimize alongside your business goals.