top of page
DPA Brand Guideline - Master (5)_edited.png

Understanding User Permissions and Access Control


Overview


Assessment Manager uses a comprehensive Role-Based Access Control (RBAC) framework to ensure users can only access the information and functionality required to perform their role.

Rather than providing every user with unrestricted access, permissions are assigned based on organisational responsibilities, helping protect sensitive information while maintaining accountability and supporting good governance.


Access controls operate at multiple levels within Assessment Manager, including Organisation, Aquatic Facility, User Role and Subscription. Together, these controls ensure information remains secure, confidential and accessible only to authorised users.


Role-based access is recognised as an information security best practice and supports organisations in meeting their governance, privacy and cyber security obligations.


Access Control Principles

Assessment Manager has been designed around the following security principles.


Principle of Least Privilege

Users are only provided with the minimum level of access necessary to perform their responsibilities.

Restricting unnecessary access reduces organisational risk, protects confidential information and minimises the likelihood of accidental or unauthorised changes.


Need-to-Know Access

Information is only available to users who require it to perform their duties.

This helps ensure confidential operational information, assessment results and improvement activities remain accessible only to authorised personnel.


Individual Accountability

Every user has their own individual account.

Using individual accounts ensures all assessments, maturity rating updates, evidence uploads, comments and improvement actions can be attributed to the person who completed them, providing transparency and accountability across the platform.


How Access is Controlled

Assessment Manager applies multiple layers of access control.


Organisation-Level Security

Each organisation operates within its own secure environment.

Users cannot access information belonging to another organisation, ensuring customer information remains segregated and confidential.


Aquatic Facility Access

Within an organisation, access may also be limited to specific aquatic facilities.

This ensures users only view information relevant to the facilities they are responsible for managing or supporting.


User Roles

Every user is assigned a role that determines what they can view, edit or administer within the platform.

Typical roles include:

  • Organisation Administrator

  • Facility Administrator

  • User

Each role provides different levels of access based on organisational responsibilities.


Subscription Permissions

Some platform functionality depends on your organisation's subscription.

Users will only see assessment types, validation services and benchmarking features included within their organisation's subscription.


Organisation Administrator Responsibilities


Organisation Administrators play an important role in maintaining the security of Assessment Manager.


Their responsibilities include:

  • Inviting new users.

  • Assigning user roles.

  • Managing organisation information.

  • Reviewing employee access.

  • Removing users who no longer require access.

  • Maintaining accurate organisational records.

  • Ensuring users have appropriate permissions.


Regular review of user access is considered an important cyber security control and helps reduce unnecessary security risks.


Secure User Management


To maintain platform security, organisations should follow recognised access management practices.


These include:

  • Providing every employee with their own account.

  • Never sharing usernames or passwords.

  • Removing access immediately when staff leave the organisation.

  • Reviewing user permissions regularly.

  • Granting administrative access only where required.

  • Updating permissions when employee responsibilities change.


These practices support good governance and reduce the risk of unauthorised access.


Audit and Accountability


Assessment Manager has been designed to provide accountability for organisational activities.

Individual user accounts help ensure assessments, evidence uploads, improvement actions and other platform activities can be associated with the appropriate user.


Maintaining individual user accounts also supports internal governance, quality assurance and continuous improvement.


Step-by-Step Instructions


Step 1: Confirm Your User Role

When you are invited to Assessment Manager, your Organisation Administrator assigns you an appropriate user role.

Your role determines the information and functionality available to you throughout the platform.


Step 2: Access Your Assigned Facilities

Once logged in, you will only have access to the organisation, aquatic facilities and platform features that have been assigned to your account.

If you cannot access a facility you believe you should manage, contact your Organisation Administrator.


Step 3: Review Your Permissions

If your responsibilities change, ask your Organisation Administrator to review your permissions.

User roles and facility access should always reflect current operational responsibilities.


Step 4: Protect Your Account

Never share your login credentials with another person.

Individual accounts protect organisational information and ensure all platform activity remains fully accountable.


Step 5: Report Incorrect Access

If you discover information that you should not be able to access, or cannot access information you require, report the issue immediately to your Organisation Administrator.

Prompt reporting helps maintain the security and integrity of organisational information.


Security Best Practice


Review user permissions regularly, particularly following organisational restructures, staff movements or changes in operational responsibilities.


Avoid assigning Organisation Administrator access unless it is genuinely required. Restricting administrative privileges is a recognised cyber security practice and helps reduce the risk of accidental or unauthorised changes.


Never share user accounts between employees. Individual accounts improve accountability, support audit processes and strengthen organisational security.

Regularly review facility access to ensure users only have visibility of information relevant to their role.


Frequently Asked Questions


Why can't I see all aquatic facilities?

Your access is determined by your assigned permissions. Depending on your role, you may only have access to one or more specific aquatic facilities within your organisation.


Why can't I access Benchmark or Secret Swimmers?

Some features are only available where they form part of your organisation's subscription and where your assigned role provides access.


Who can change my permissions?

Only an Organisation Administrator can update your user role, facility access and administrative permissions.


Why shouldn't employees share accounts?

Shared accounts reduce accountability, increase security risks and make it difficult to determine who has completed assessments, uploaded evidence or updated organisational information.


How often should user permissions be reviewed?

Organisation Administrators should review user access regularly and immediately following staff changes, role changes or employee departures to ensure permissions remain accurate and appropriate.


What should I do if I believe someone has inappropriate access?

Report the issue immediately to your Organisation Administrator so that permissions can be reviewed and corrected if necessary.

bottom of page