ResourcesPlatform guidePart 7
Built-in and custom roles, permissions, department visibility, audit trail, GDPR, and security.
Not everyone in a biotech company needs the same level of access. A Clinical Research Associate creating purchase orders has different needs from a Finance Manager reviewing invoices, and both differ from a Chief Operating Officer who oversees all procurement activity.
Roles and permissions in biosuite ensure that each person sees and does only what is relevant to their responsibilities. This protects sensitive data, prevents unauthorised changes, and supports compliance – all without creating friction for daily work.
Every user in biosuite is assigned a role. A role defines what the user can see and do across the system.
On the Starter plan, there are two built-in roles:
On the Professional and Advanced plans, additional built-in roles are available:
You can also create custom roles on the Advanced plan, tailored to your company's specific needs.
Each role is defined by a set of permissions. A permission controls access to a specific area of biosuite – for example, suppliers, contracts, purchase orders, invoices, or settings.
For each area, a role can have one of several access levels:
The exact levels available depend on the area. Some areas only support view or none, while others support the full range.
Example: A user with the "Finance" role might have view access to contracts and suppliers, create & edit access to invoices, and none for settings management. This means they can process invoices and review contracts, but cannot change company settings or create new suppliers.
On the Advanced plan, administrators can create custom roles to match their company's structure.
Example: You might create a "Clinical Operations Lead" role that has create and edit access to suppliers, contracts, and purchase orders, but view-only access to invoices and no access to company settings. This is useful when a team lead needs to manage procurement for their department but should not be changing company-wide settings.
Custom roles can be renamed or deleted as your needs evolve. If a custom role is deleted, users assigned to it are reassigned to the standard "User" role.
Role management is available from the company settings.
Administrators with the appropriate permissions can:
biosuite distinguishes between two types of role management access:
This distinction ensures that the ability to define new roles can be separated from the ability to adjust what existing roles can do.
Built-in roles (Admin, User, Finance, View-only) cannot be deleted or renamed. Their permissions can be adjusted to suit your company's needs.
In addition to role-based permissions, biosuite supports department-based visibility to control who can see specific records.
Every supplier, contract, purchase order, and invoice can be set to one of two visibility levels:
This is useful when different teams handle different suppliers or projects and should not see each other's procurement activity.
Example: The Clinical Operations team works with a specific CRO and creates purchase orders for clinical trial services. By setting these records to "Department" visibility, only Clinical Operations team members and administrators can see them. The CMC team, working with different suppliers, sees only their own records.
Department visibility is inherited automatically down the document chain. If a purchase order is set to department visibility, any invoices linked to it automatically inherit the same restriction. This prevents accidental exposure when new documents are created against restricted records.
To ensure approvals are not blocked by visibility restrictions, approvers can always see the purchase orders assigned to them for review – regardless of department settings.
biosuite maintains a comprehensive audit trail that records every significant action in the system.
This includes:
Each entry records what happened, who did it, and when. The audit trail is accessible from the control center.
This level of traceability supports internal compliance reviews, management oversight, and audit preparation. You do not need to reconstruct what happened from scattered emails or spreadsheets – biosuite keeps a single, reliable record.
biosuite is designed with data privacy in mind.
Key principles:
For full details, please refer to the biosuite Privacy Policy.
biosuite includes several measures to protect your account:
If you suspect unauthorised access to your account, change your password immediately from your profile.
Every company in biosuite is completely isolated from every other company.
Users in one company cannot see, access, or interact with data belonging to another company. This isolation is enforced at every level – from the data stored in the system to the permissions that control access.
If a user has access to multiple companies, each company is treated as a separate, independent environment. Switching between companies does not carry over any data or permissions.
This ensures that your procurement data, team information, and financial records are always private to your organisation.