BlogProduct updates
September 28, 2023

Introducing expanded Role-Based Access Control

Written by
Joe Goldberg
Product Marketing
Alan Wang, Engineering
Sanjay Padval
Reviewed by
No items found.

Accelerating security solutions for small businesses 

Tagore offers strategic services to small businesses. 

A partnership that can scale 

Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate.

Standing out from competitors

Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

Today we’re thrilled to announce that Vanta’s Role-Based Access Control (RBAC) functionality has gotten even stronger with new capabilities, including:

  • Additional pre-built roles now available in Vanta
  • The ability to create custom roles, each with their own access and permission rights. 

These expanded RBAC capabilities are now generally available and demonstrate Vanta’s continued commitment to supporting the needs of larger, more advanced organizations through additional customization and flexibility across our platform. 

What is Role-Based Access Control?

Role-Based Access Control is control over user groups and access to resources based on a defined role. In software applications, it’s important to ensure that users have the appropriate permissions and can only view data or perform actions required for their role, consistent with the “principle of least privilege.” RBAC is especially important for applications that contain or connect to sensitive data and in cases where multiple teams and employees need different levels of access to software. And for larger, maturing organizations, flexible RBAC functionality is typically a requirement for compliance, risk, or cybersecurity applications. 

Vanta previously came with three pre-built roles — Admins, Editors and Employees. This met the needs of most customers. but some needed additional flexibility and role customization. 

Expanded RBAC in Vanta

With Vanta’s expanded RBAC capabilities, customers now have this additional flexibility and customization. The new functionality includes:

Two additional pre-built roles aimed at specific user types

View-only Administrator role: This role gives view-only access to everything in Vanta. Since View-only Administrators do not have the ability to edit or change any configurations, this role is appropriate for users (such as senior security or compliance executive) who need to be able to view information in Vanta but aren’t involved in any configuration or administrative changes.

Sales Administrator role: This role can view basic information and manage external access to an organization's public Trust Report powered by Vanta. This role is appropriate for sales team members who are working with prospects evaluating their offering. If a prospect requests a sensitive compliance document through a Trust Report, Sales Administrators can approve the request or deny access if the requester is unknown.

These additional pre-built roles are now available in Vanta to all customers at no additional cost. Stay tuned for more pre-built roles in the coming months.

Two new prebuilt roles are now available on the Roles page.

Custom roles

Vanta now lets you create an unlimited number of custom roles, each with their own granular view and edit permissions to all areas of the Vanta interface. This flexibility is especially important for larger organizations with many teams and employees requiring different levels of access to Vanta. 

For example, you can create a “Vendor security review” role for users that only need access to the Vendors tab  to perform security and risk reviews of third-party vendors. For team members in your Legal department, you might create a “Legal” role that can only view and edit policies in Vanta. 

Custom role creation is now available to Vanta customers at an additional cost. To learn more about pricing, please reach out to your account executive or contact us here.

For each custom role, you can set granular view and access permissions.

Permission details page

Last but not least, Vanta’s new ”Permission details” page gives Administrators a bird’s-eye view of the different  view, edit, and no access permission levels across pre-built and custom roles. This makes it easy for Administrators to quickly get an understanding of the various roles they have in Vanta or where they might need to make adjustments.

Permission details page with bird's-eye view of roles and permissions.

Get started with expanded RBAC in Vanta 

Current customers can now access the new pre-built roles in Vanta here. If you’re interested in learning more about custom roles or additional customization capabilities, reach out to your account executive or customer success manager or contact us here. 

Access Review Stage Content / Functionality
Across all stages
  • Easily create and save a new access review at a point in time
  • View detailed audit evidence of historical access reviews
Setup access review procedures
  • Define a global access review procedure that stakeholders can follow, ensuring consistency and mitigation of human error in reviews
  • Set your access review frequency (monthly, quarterly, etc.) and working period/deadlines
Consolidate account access data from systems
  • Integrate systems using dozens of pre-built integrations, or “connectors”. System account and HRIS data is pulled into Vanta.
  • Upcoming integrations include Zoom and Intercom (account access), and Personio (HRIS)
  • Upload access files from non-integrated systems
  • View and select systems in-scope for the review
Review, approve, and deny user access
  • Select the appropriate systems reviewer and due date
  • Get automatic notifications and reminders to systems reviewer of deadlines
  • Automatic flagging of “risky” employee accounts that have been terminated or switched departments
  • Intuitive interface to see all accounts with access, account accept/deny buttons, and notes section
  • Track progress of individual systems access reviews and see accounts that need to be removed or have access modified
  • Bulk sort, filter, and alter accounts based on account roles and employee title
Assign remediation tasks to system owners
  • Built-in remediation workflow for reviewers to request access changes and for admin to view and manage requests
  • Optional task tracker integration to create tickets for any access changes and provide visibility to the status of tickets and remediation
Verify changes to access
  • Focused view of accounts flagged for access changes for easy tracking and management
  • Automated evidence of remediation completion displayed for integrated systems
  • Manual evidence of remediation can be uploaded for non-integrated systems
Report and re-evaluate results
  • Auditor can log into Vanta to see history of all completed access reviews
  • Internals can see status of reviews in progress and also historical review detail
FEATURED VANTA RESOURCE

The ultimate guide to scaling your compliance program

Learn how to scale, manage, and optimize alongside your business goals.