Who can do what

A visual map of every persona in the app. Switch on Edit configuration to change what each persona should be allowed to do — your changes are saved on this device and can be exported as JSON so they can later be applied to the app's real rules.

Administrator

Configuration and recovery seat. Owns the templates and bypasses every workflow guard.

Allowed
  • Set OneQMS / Entity level on any chapter or task in Audit Template
  • Assign OneQMS owners and attach OneQMS files and reference links
  • Select which regs and tasks are in scope for an audit
  • Select and de-select framework chapters and tasks for an audit
  • Verify, re-open, re-assign and re-date any prep task
  • Open every page, pop-out and console, and act as any person
Not allowed
  • Nothing is blocked — every change is written to the task history
Audit TemplateAudit PrepEntity PrepSME WorkspaceRoles & PermissionsBusiness Rules

Preparation action matrix

Template configuration, audit scoping, SME assignment and the task lifecycle (Not Started → In Progress → Submitted for Review → Verified, with Rework Requested as the only way back).

ActionMovesAdministratorHostATMS RequestorBack Room LeadStream LeadStream SupportReg ComplianceSMERequest SupportScribeJJRC SME Prep
Set OneQMS / Entity levelAudit Template item → level
Assign OneQMS owner, files & linksOneQMS item → central evidence
Select / de-select chapters & tasksCatalogue → audit scope
Assign SMEs to a taskUnassigned → assigned
Set or change the due dateTask → due date
Start work on a taskNot Started → In Progress
Upload attachments & reference linksTask → evidence
Add a free-text commentTask → comment thread
Submit evidence for reviewIn Progress / Rework → Submitted for Review
Verify the taskSubmitted for Review → Verified
Request rework with feedbackSubmitted for Review → Rework Requested
Ping the assigned SMEsTask → Teams + email chase
Define the entity's Audit RosterEntity → default streams & team
Create a new audit for an entityEntity → audit
Add or remove an entity favouriteChoose an Entity → working list

Verification is deliberately separated from preparation: nobody verifies evidence they produced themselves.

Live request lanes — entity console

Applies to the Back Room Lead console embedded on the entity readiness page, where requests raised during the audit move between lanes. Derived from the rules the app actually enforces.

ActionMovesAdministratorHostATMS RequestorBack Room LeadStream LeadStream SupportReg ComplianceSMERequest SupportScribeJJRC SME Prep
Assign SMENew Request → SME Assigned, pending SME confirmation
Confirm I'm working on this + ETASME Assigned, pending SME confirmation → SME confirmed, in progress
Reject requestSME Assigned, pending SME confirmation → Stuck
Request Regulatory Compliance supportSME Assigned, pending SME confirmation, SME confirmed, in progress → Compliance Support requested
Confirm ready for Backroom reviewSME confirmed, in progress → Backroom review
Confirm Request/SME ready for Front RoomBackroom review → Request/SME ready
Needs reworkBackroom review → SME confirmed, in progress
Move to Front RoomRequest/SME ready → In Front Room
CloseIn Front Room → Closed
Create follow-up requestIn Front Room
CompletedCompliance Support requested → Backroom review
Send to ClarificationNew Request, SME Assigned, pending SME confirmation, SME confirmed, in progress, Backroom review → Clarification
Send to StuckNew Request, SME Assigned, pending SME confirmation, SME confirmed, in progress, Backroom review → Stuck

† Facilitator take-over: when a Request Facilitator is assigned to a request, the Facilitator performs these actions instead of the SME.

Rules that apply to everyone

  • SMEs act only on tasks they are assigned to — every other task opens read-only.
  • Only the Compliance seat verifies a task, and only after evidence has been submitted for review.
  • Rework always requires written feedback; it is stored on the task and shown to the SME.
  • Assignment notifications (Teams + email) are only sent on the explicit Assign action, never while picking names.
  • OneQMS / Entity level is set in Audit Template only; Audit Prep and Entity Prep display it read-only.
  • Audit Prep shows the items already in the audit; the scope itself is changed from “Select regs and tasks in scope”.
  • Every status change, verification, rework and ping is written to the task history with actor and timestamp.