Docupath uses role-based access control (RBAC) to manage what each user can see and do. There are six roles: Administrator, Manager, Reviewer, Validator, Reviewer & Validator, and Custom.
Document-centric roles (Reviewer, Validator, Reviewer & Validator, and Custom) can be mapped to specific organizations for multi-tenant deployments. Assign roles using the principle of least privilege - give users only the access they need for their function.
How It Works
Understanding the Role Hierarchy
Roles range from broadest to narrowest access:
Administrator - full access to all system settings, documents, user management, and integrations
Manager - broad visibility and monitoring across the platform; no access to Instruction Builds
Reviewer, Validator, Reviewer & Validator, and Custom - document-centric roles, scoped to the organizations they are assigned to
Administrator Role
Full access to all system settings, documents, user management, and integrations. Reserved for platform owners and IT/compliance leadership. Because it carries complete control, grant this role only where it is genuinely required.
Manager Role
Broad visibility across the platform, including monitoring workflows and usage insights. A Manager does not have access to Instruction Builds. Typically assigned to business leads who oversee operations without configuring the system.
Reviewer Role
Reviews documents, makes edits, and decides whether to approve or reject them. A common fit for staff who process documents day to day, such as an external accounts payable clerk.
Validator Role
Can edit and validate documents but cannot approve or reject them. Useful when you want to separate validation from approval to create a multi-step review.
Reviewer & Validator Role
Combines the capabilities of both Reviewer and Validator, allowing full document handling - edit, validate, and approve or reject.
Custom Role
A configurable user role. You choose whether the user acts as a Reviewer, a Validator, or both, and you control which Docupath features they can access - for example, Manage organizations, Instruction builds, and Supporting files. Use Custom when none of the predefined roles matches a user's exact responsibilities.
Supported Configurations and Options
Role | Capabilities |
Administrator | Full access to all system settings, documents, user management, and integrations |
Manager | Broad visibility and monitoring across the platform; no access to Instruction Builds |
Reviewer | Review, edit, and approve or reject documents |
Validator | Edit and validate documents; cannot approve or reject |
Reviewer & Validator | Full document handling (Reviewer + Validator capabilities) |
Custom | Configurable as Reviewer, Validator, or both, with selectable access to specific features (e.g., Manage organizations, Instruction builds, Supporting files) |
Other Technical Specifications
Aspect | Details |
Access control model | Role-based access control (RBAC) |
Organization scope | Document-centric roles (Reviewer, Validator, Reviewer & Validator, Custom) can be mapped to specific organizations |
Self-Service Access | When enabled, document-centric users see only documents they uploaded or that are assigned to their organization; available for Reviewer, Validator, Reviewer & Validator, and Custom roles. When disabled, users follow standard visibility rules based on their role. |
User invitation & status | New users receive an email invitation and show as "Pending Invite" until they accept |
Audit trails | Role management is designed to support complete, transparent audit trails |
Role Assignment Best Practices
Principle of Least Privilege
Start users with the lowest role that lets them do their job - Reviewer or Validator - and only escalate to Manager or Admin if required. Reserve Administrator for users who genuinely need full control.
Role Assignment Workflow
Add the user: Go to Settings → Manage Users, click Add User, and enter their Name, Email, and Role. Optionally assign an Organization if their work involves documents specific to that entity.
Match the role to the user's function, for example:
External AP clerk → Reviewer or Reviewer & Validator
Business lead → Manager
Platform owner → Admin
Scope document access: For document-centric roles, set the organization and Self-Service Access so users see only the documents they should.
Send the invitation: The user shows as "Pending Invite" until they accept. Use corporate email addresses for clean audit records.
Role Change Management
To change a user's role, edit their account under Settings → Manage Users.
If a user has too much access, scale them back to Reviewer or Validator.
If a user can't approve documents, assign Reviewer or Reviewer & Validator.
If a user can't see documents, check their organization assignment and Self-Service settings.
If a user is stuck in "Pending Invite," resend the invitation or confirm it wasn't caught in spam/junk.
Review role assignments quarterly to maintain compliance, and avoid shared accounts so actions remain accountable.
Notes
Manager has no Instruction Builds: The Manager role cannot access Instruction Builds.
Custom role: Lets you set Reviewer/Validator capabilities and grant access to specific features such as Manage organizations, Instruction builds, and Supporting files.
Self-Service Access: Controls document visibility for document-centric roles and is useful for onboarding external partners, vendors, or distributed regional teams.
Account hygiene: Use corporate email addresses for traceability, and avoid shared accounts for accountability.
