VeritomeHelp Centre
/
Browse documentation
Getting started

Invite your team and assign owners

Add colleagues, pick from six least-privilege roles, keep the org profile that feeds your documents, and assign obligation owners so work is accountable.

Updated Veritome documentation

Veritome is multi-tenant: everything you create lives inside your organisation and is never visible to another. Organisation (under Configure) is where you manage who is in your workspace, what each person can do, and the organisation-level details that flow onto your regulatory documents.

Who can change these settings? Organisation profile, members, roles, billing, security and integrations are Org admin capabilities. Keep at least two Org admins so you are never locked out.

Organisation profile

Go to Organisation → Organisation profile. This is not just housekeeping — the fields here are pulled straight into your paperwork:

  1. Enter your legal entity name, country, registered address and contact email exactly as they appear on official filings. The contact email and country are what mark the profile complete on the first-run checklist.
  2. Add your identifiers (registration number, legal form, organisation type, website) and your size band (EU Recommendation 2003/361).
  3. Save. From now on these values pre-fill the provider identity block on the EU declaration of conformity (Art. 47) and the Annex VIII / Art. 49 EU-database registration sheet.

The built-in roles

Veritome ships six system roles, from full control to read-only. Roles are least-privilege: give each person the narrowest role that still lets them do their job.

RoleCan doTypical holder
Org adminEverything — billing, members, security, integrations, and all compliance work.Owner / DPO / compliance lead
Compliance managerFull read/write compliance, approves tasks and documents, generates reports. Gets the approvals queue on the Dashboard.Compliance manager
Compliance officerCreates and edits systems, completes tasks, fills smart forms, submits for approval. Cannot approve their own work.Day-to-day operator
System ownerManages only their assigned systems — scoped access, cannot see others.Product / system owner
Legal counselRead access across all systems and documents; can review forms before approval. Cannot edit operational data.In-house / external counsel
AuditorRead-only everywhere; can export reports and download approved PDFs.Internal audit / external reviewer

The four-eyes principle is built in: a Compliance officer can submit an obligation on a high-risk system, but only a Compliance manager or Org admin can mark it Complete — the separation regulators expect on high-risk systems. The approvals waiting appear on the Dashboard.

In the Roles view each system role has an Active toggle — deactivate a role you do not use to keep the invite list tidy (Org admin is always active). Admins can edit a role's permissions with the toggles in the role detail: a custom role is changed in place, while saving edits to a built-in role creates an editable (copy) owned by your organisation and moves its members across — the built-ins themselves are shared and never change. Org admin cannot be edited: it always holds every permission. Build custom roles from scratch with Create custom role, or Clone an existing role and edit the copy.

App roles vs. operator roles — do not confuse them

  • App roles (above) control who can click what inside Veritome.
  • Operator rolesProvider / Deployer / Importer / Distributor — are what the EU AI Act assigns to your organisation for a given system, and they decide which legal obligations apply. You set the operator role in the classification flow, not here.

One person can be an Org admin in the app while your organisation is a Deployer under the Act. Keep the two mental models separate. A third thing, your position (compliance, engineering, DPO …), is what the first-run wizard asked; it tunes defaults and nothing else.

Inviting a teammate

  1. In the Members view, press Invite member.
  2. Enter their email (required) and, optionally, their name.
  3. Pick a role. New invitees default to Compliance officer — change it if they need more or less.
  4. Send. They receive an email link to set a password and join.

At your seat limit? The invite is blocked and the banner explains it — the plan caps members (fifteen during early access). Remove someone first, or wait for paid plans to open (see Plans, billing and upgrades).

Use Edit to change a member's name or role, or Reset password → to email them a secure set-a-new-password link. Remove revokes access immediately — reassign any obligations they owned first. Under Organisation → Security an admin can require two-factor authentication for every member; each person enrols from the first-run checklist or their own settings.

Assigning obligation owners

Roles are also how you make accountability explicit. In the obligation drawer — from a system's Obligations tab or the Obligations register — you assign an owner to each duty. Owners get the reminders (upcoming due dates, expiring evidence) and show up on the dossier as the responsible person, turning "someone should do this" into "this person owns it". The Dashboard treats an unowned duty as a gate: until every duty has an owner, the work beneath it is shown locked, without dates.

Audit trail and data isolation

Every meaningful action — a classification confirmed, an obligation updated, a dossier sealed, a review completed, a member invited — is written to the Audit trail (under Prove it). It is the hash-chained, daily-anchored record of who did what and when, which is evidence of your governance decisions for an auditor. It is not the AI system's own Art. 12 logs, which stay with the system. Because Veritome often holds data about AI systems that themselves process personal data, it is org-isolated by default and access is enforced on every request — evidence files, dossiers and reports never leave your organisation's scope.