ResourcesPlatform guidePart 7

    Part 7: Roles, permissions & security

    Built-in and custom roles, permissions, department visibility, audit trail, GDPR, and security.

    Not everyone in a biotech company needs the same level of access. A Clinical Research Associate creating purchase orders has different needs from a Finance Manager reviewing invoices, and both differ from a Chief Operating Officer who oversees all procurement activity.

    Roles and permissions in biosuite ensure that each person sees and does only what is relevant to their responsibilities. This protects sensitive data, prevents unauthorised changes, and supports compliance – all without creating friction for daily work.

    Every user in biosuite is assigned a role. A role defines what the user can see and do across the system.

    On the Starter plan, there are two built-in roles:

    • Admin – full access to manage the company, including settings, team, and all procurement data
    • User – access to day-to-day procurement features such as viewing suppliers, contracts, and creating purchase orders (on Professional and above)

    On the Professional and Advanced plans, additional built-in roles are available:

    • Finance – designed for finance team members who need access to invoices, ERP-related features, and financial oversight
    • View-only – read-only access for stakeholders who need visibility without the ability to make changes

    You can also create custom roles on the Advanced plan, tailored to your company's specific needs.

    Each role is defined by a set of permissions. A permission controls access to a specific area of biosuite – for example, suppliers, contracts, purchase orders, invoices, or settings.

    For each area, a role can have one of several access levels:

    • None – no access to this area
    • View – can see the data but not make changes
    • Create – can add new records (for example, create a new supplier) but not edit existing ones
    • Edit – can modify existing records
    • Create & edit – full access to both create and modify records

    The exact levels available depend on the area. Some areas only support view or none, while others support the full range.

    Example: A user with the "Finance" role might have view access to contracts and suppliers, create & edit access to invoices, and none for settings management. This means they can process invoices and review contracts, but cannot change company settings or create new suppliers.

    On the Advanced plan, administrators can create custom roles to match their company's structure.

    Example: You might create a "Clinical Operations Lead" role that has create and edit access to suppliers, contracts, and purchase orders, but view-only access to invoices and no access to company settings. This is useful when a team lead needs to manage procurement for their department but should not be changing company-wide settings.

    Custom roles can be renamed or deleted as your needs evolve. If a custom role is deleted, users assigned to it are reassigned to the standard "User" role.

    Role management is available from the company settings.

    Administrators with the appropriate permissions can:

    • view all roles and their permission assignments
    • create new custom roles
    • rename or delete custom roles
    • adjust the permissions for each role

    biosuite distinguishes between two types of role management access:

    • Create access – allows creating, renaming, and deleting roles (structural changes)
    • Edit access – allows changing the permission assignments within existing roles

    This distinction ensures that the ability to define new roles can be separated from the ability to adjust what existing roles can do.

    Built-in roles (Admin, User, Finance, View-only) cannot be deleted or renamed. Their permissions can be adjusted to suit your company's needs.

    In addition to role-based permissions, biosuite supports department-based visibility to control who can see specific records.

    Every supplier, contract, purchase order, and invoice can be set to one of two visibility levels:

    • All – visible to everyone in the company (this is the default)
    • Department – visible only to users in the same department, plus administrators

    This is useful when different teams handle different suppliers or projects and should not see each other's procurement activity.

    Example: The Clinical Operations team works with a specific CRO and creates purchase orders for clinical trial services. By setting these records to "Department" visibility, only Clinical Operations team members and administrators can see them. The CMC team, working with different suppliers, sees only their own records.

    Department visibility is inherited automatically down the document chain. If a purchase order is set to department visibility, any invoices linked to it automatically inherit the same restriction. This prevents accidental exposure when new documents are created against restricted records.

    To ensure approvals are not blocked by visibility restrictions, approvers can always see the purchase orders assigned to them for review – regardless of department settings.

    biosuite maintains a comprehensive audit trail that records every significant action in the system.

    This includes:

    • purchase order creation, submission, approval, rejection, and archiving
    • amendment requests, approvals, and rejections
    • invoice submissions and receipt confirmations
    • team changes (invitations, role updates, access removal)
    • settings changes (categories, currencies, company details)
    • data exports
    • plan changes

    Each entry records what happened, who did it, and when. The audit trail is accessible from the control center.

    This level of traceability supports internal compliance reviews, management oversight, and audit preparation. You do not need to reconstruct what happened from scattered emails or spreadsheets – biosuite keeps a single, reliable record.

    biosuite is designed with data privacy in mind.

    Key principles:

    • You own your data – the data you enter into biosuite remains yours. biosuite processes it only to provide the service.
    • No advertising use – your data is never used for advertising or shared with third parties for marketing purposes.
    • EU hosting priority – data is hosted within the European Union. Where trusted infrastructure providers operate outside the EU, appropriate GDPR safeguards (including Standard Contractual Clauses) are applied.
    • Data portability – you can export your data at any time using the CSV and Excel export features. There is no lock-in.
    • Deletion and anonymisation – when a user account is removed, personal data is anonymised while preserving the integrity of historical records. When a company is fully deleted, all associated data and files are permanently removed.

    For full details, please refer to the biosuite Privacy Policy.

    biosuite includes several measures to protect your account:

    • Email verification – every account must be verified via email before it can be used
    • Password protection – passwords must meet minimum security requirements
    • Rate limiting – repeated failed login attempts are temporarily blocked to prevent unauthorised access
    • Session management – sessions are managed securely, and signing out clears all active session data

    If you suspect unauthorised access to your account, change your password immediately from your profile.

    Every company in biosuite is completely isolated from every other company.

    Users in one company cannot see, access, or interact with data belonging to another company. This isolation is enforced at every level – from the data stored in the system to the permissions that control access.

    If a user has access to multiple companies, each company is treated as a separate, independent environment. Switching between companies does not carry over any data or permissions.

    This ensures that your procurement data, team information, and financial records are always private to your organisation.