VeritomeHelp Center
/

Invite your team and assign owners

Add colleagues, pick from six least-privilege roles, keep the org profile that feeds your documents, and assign obligation owners so work is accountable.

Updated 15.07.2026

Veritome is multi-tenant: everything you create lives inside your organisation and is never visible to another. Settings is where you manage who's in your org, what each person can do, and the org-level details that flow onto your regulatory documents.

Who can change these settings? Organisation profile, members, roles, billing, security and integrations are all Org admin capabilities. Keep at least two Org admins so you're never locked out.

Organisation profile

Go to Settings → Organisation profile. This isn't just housekeeping — the fields here are pulled straight into your compliance paperwork:

  1. Enter your legal entity name, registered address and contact details exactly as they appear on official filings.
  2. Add your identifiers (e.g. company registration / VAT number) where prompted.
  3. Save. From now on these values pre-fill the provider identity block on the EU Declaration of Conformity (Art. 47) and the Annex VIII / Art. 49 EU-database registration sheet.

The built-in roles

Veritome ships six system roles, from full control to read-only. Roles are least-privilege: give each person the narrowest role that still lets them do their job.

RoleCan doTypical holder
Org adminEverything — billing, members, security, integrations, and all compliance work.Owner / DPO / compliance lead
Compliance managerFull read/write compliance, approves tasks & documents, generates reports. Gets the approvals queue on the dashboard.Compliance manager
Compliance officerCreates & edits systems, completes tasks, fills smart forms, submits for approval. Cannot approve their own work.Day-to-day operator
System ownerManages only their assigned systems — scoped access, can't see others.Product / system owner
Legal counselRead access across all systems & documents; can review forms before approval. Cannot edit operational data.In-house / external counsel
AuditorRead-only everywhere; can export reports and download approved PDFs.Internal audit / external reviewer

The four-eyes principle is built in: a Compliance officer can submit a high-risk document, but only a Compliance manager (or Org admin) can approve it — the separation regulators expect on high-risk systems.

In the Roles view each system role has an Active toggle — deactivate a role you don't use to keep the invite list tidy (Org admin is always active). Admins can also edit a role's permissions with the toggles in the role detail: a custom role is changed in place, while saving edits to a built-in role creates an editable "(copy)" owned by your organisation and moves its members across — the built-ins themselves are shared and never change. Org admin cannot be edited: it always holds every permission. You can also build custom roles from scratch: click Create custom role, name it, tick exactly the permissions it should hold, or Clone an existing role and edit the copy.

App roles vs. operator roles — don't confuse them

  • App roles (above) control who can click what inside Veritome.
  • Operator rolesProvider / Deployer / Importer / Distributor — are what the EU AI Act assigns to your organisation for a given system, and they decide which legal obligations apply. You set the operator role in the classification wizard, not here.

One person can be an Org admin in the app while your organisation is a Deployer under the Act. Keep the two mental models separate.

Inviting a teammate

  1. In the Members view, click Invite member.
  2. Enter their email (required) and, optionally, their name.
  3. Pick a role from the dropdown. New invitees default to Compliance officer — change it if they need more or less.
  4. Click Send invite. They receive an email link to set a password and join.

At your seat limit? The invite is blocked and the banner explains it — your plan caps team members. Upgrade, or remove someone first (see Plans, billing and upgrades).

Use Edit (pencil) to change a member's name or role, or Reset password → to email them a secure set-a-new-password link. Remove (bin) revokes access immediately — reassign any obligations they owned first.

Assigning obligation owners

Roles are also how you make accountability explicit. In a system's obligation tabs (and on the Obligations board) you assign an owner to each duty. Owners get the reminders (upcoming due dates, expiring evidence) and show up on the dossier as the responsible person — turning "someone should do this" into "this person owns it".

Audit log and data isolation

Every meaningful action — a classification confirmed, an obligation updated, a dossier sealed, a review completed, a member invited — is written to the audit log at Settings → Audit. It's the tamper-evident record of who did what and when, which supports an Art. 12 record-keeping and Art. 26(6) logging story. Because Veritome often holds data about AI systems that themselves process personal data, it is org-isolated by default and access is enforced on every request — evidence files, dossiers and reports never leave your organisation's scope.

Need to act on this?Open Veritome