OpsIQ
OpsIQ·One
Control Plane · Identity

Identity & Roles

Roles, permissions and access scope. Approver-requester separation is enforced organization-wide.

248 users9 roles12 capabilities
Last access review14 days ago · 0 findings
ProvisioningManual today · SCIM planned (v6.0 ENT)
Separation of dutiesApprover ≠ requester · enforced

Role catalog

Organization Owner
Scope · Org
Full tenant control. One per organization recommended.
2 users
active
Executive
Scope · Org
Read everything; approve high-impact recommendations.
11 users
active
VP
Scope · BU
Govern a business unit; approve mid-impact actions.
14 users
active
Director
Scope · LOB
Run an LOB end-to-end.
28 users
active
Manager
Scope · Site
Operate a site or LOB segment.
46 users
active
Supervisor
Scope · Team
Lead a team. Coach agents and execute actions.
92 users
active
Analyst
Scope · BU
Build reports and run scenarios.
21 users
active
Read-only User
Scope · Org
View dashboards; no changes.
32 users
active
Administrator
Scope · Org
Manage settings, connectors, users — not business data.
2 users
active

Permissions matrix

Full · Scoped (own slice only) · None.

CapabilityOrganizationExecutiveVPDirectorManagerSupervisorAnalystRead-onlyAdministrator
View
View operational dataS
View financial dataSSS
View audit logsSS
Act
Approve recommendationsSS
Execute actionsSS
Assign actions to othersS
Manage
Manage users & roles
Manage organization settings
Manage KPI thresholdsSS
Manage data sources & importsSS
Manage AI settingsS
Export
Export data & reportsSS

Approval thresholds

When auto-execute is allowed vs requires a named approver.

Auto-execute
Confidence ≥ 95% AND impact ≤ $25k
Approver: None — logged
Single approver
Confidence ≥ 85% OR impact ≤ $250k
Approver: Director or VP
Dual approver
Impact > $250k OR regulatory exposure
Approver: VP + Executive
Control Plane · Identity & RolesApprover ≠ requester · enforced
The Enterprise Operating SystemSOC 2 Type II · ISO 27001 · HIPAA-ready
© 2026 OpsIQ · Atlas Intelligence Engine