Skip to main content
Help Centre Risk Register Manager permissions on risks

Manager permissions on risks

What this is

Managers can view every risk in the organisation read-only. Managers can edit, start monitoring, retire, restore, mark reviewed, and change treatment only on risks where they are the risk owner or the review owner. Owner, admin, and director users can act on any risk. Learners have no access.

What to do

As a manager, open the Risk Register list to see all risks. Open a risk you do not own — the detail page renders read-only. Open a risk you do own — edit, start monitoring, retire/restore, mark reviewed, and treatment actions all become available.

Why it matters

Read-all preserves manager visibility into the organisation's governance position; edit-owned-only preserves accountability. The same pattern applies to the Asset Register.

What happens next

Managers cannot create new risks in the MVP. Add-risk affordances appear only for owner / admin / director.

© 2026 Cleverer. Human-layer cyber compliance for Australian business.