How to Configure GSP – Risk Permissions: A Practical Guide for Smarter Access Control
Theja Siriwardena
Senior Business Analyst
Reading Time : 5 mins
Published Date : April 29, 2025

When it comes to managing organisational risk, who sees what - and who can do what - is just as important as the risks themselves. That is where GSP - Risk permissions come into play.

Whether you are in local government, finance, healthcare, or beyond, setting up the right permissions ensures accountability, compliance, and control across all risk records. In this guide, we will walk you through the two types of permissions, show you step-by-step setups, highlight use cases across industries, and finish with handy tips and tricks to get the most out of your GSP - Risk configuration.

Understanding the Two Types of GSP - Risk Permissions

GSP – Risk uses a dual-permission structure to give you complete control:

1. Standard Roles

These are pre-configured permissions applied by default within your system’s settings. They’re tied to the responsibilities users hold on specific records, for example, as a Risk Owner or Action Owner.

Use case: You want a Risk Owner to edit risks but not add new controls — no problem, simply untick that ability in their standard role settings.

2. Role Management (Flexible Permissions)

These are custom-built roles you can create, edit, and delete — linked to specific hierarchies, business units, or departments.

Use case: A Finance Risk Manager should only see risks under the “Treasury” unit — easy to set up via Role Management with hierarchical node restrictions.

Want to see these two permission types in action? Watch this on demand webinar walkthrough (00:48 – 02:20) to understand the distinctions and real-world applications.

To know more about the technical differences between static and flexible permissions, refer to the GSP – Risk Permissions and Staff Management Release Note – Sections 2 and 3.

How to Access and Configure Standard Roles

Step-by-Step Setup for Standard Roles:

1.Go to the mega menu in GSP – Risk.

2.Navigate to: Risk Settings > Standard Roles.

3.You will see a list of system-defined roles (e.g., Responsible Officer, Risk Owner).

4.Click on Edit for any role to configure permissions.

5.Tick/untick the abilities like:

  • Add/edit risks
  • Add controls
  • Assign actions

Example: Amanda Scott is assigned the role of Responsible Officer for a risk. By default, this role allows her to edit and assign actions. However, if the “Add Actions” permission is unticked in her role settings, that functionality will be disabled.

See a live demo of restricting Amanda Scott’s role permissions in this webinar segment (06:22 – 07:00), showing how to prevent specific actions like adding new controls or actions.

To understand how permissions affect risk approval workflows, refer to the “Risk Preparer” and “Risk Approver” notes in the “Risk Preparing and Approving” section. This outlines the specific visibility and editing rights granted at each stage of the approval process.

How to Create and Manage Roles Using Role Management

Role Management lets you define permissions with more granularity.

To access Role Management:

  • Go to: Mega Menu > Administration > Role Management
  • Select GSP – Risk under the product dropdown

To create a new custom role:

  • Click Add New.
  • Name the role (e.g., “Strategic Viewer – View Only”).
  • Select the hierarchy node(s) the role should apply to (e.g., Corporate Strategy).
  • Choose the Register and Functional Permissions:
    • View only, View + Edit, or Full Access
  • Assign the role to specific users under: Administration > Staff.

Pro Tip: Assign multiple roles to the same user at different levels for hybrid access (e.g., edit rights in one department and view-only in others).

For a hands-on walkthrough of assigning Amanda Scott to a specific hierarchy node using Role Management, check out this webinar example (08:55 – 10:32).

To explore the full set of permission options available in Role Management — including Strategic, Operational, and Project Risk – refer to Section 3: Risk – Flex Permissions in the Release Note.

Real-World Use Cases Across Industries

Local Government

Pain Point: Risk Officers need visibility across the council but should not edit records outside their division.

Solution: Assign ‘View Node Only’ permissions for broader insight and full access in their own division.

Finance

Pain Point: Auditors need to see confidential risk items but should not change or comment on them.

Solution: Use Standard Role permissions to enable risk-wise confidentiality, granting auditors view-only access to confidential risk items while restricting editing and commenting capabilities.

Healthcare

Pain Point: Clinical Risk Managers should preview draft risks awaiting approval.
Solution: Enable “Show Risk Prior to Approved Stage” permission to give them filtered visibility of unapproved records.

These scenarios are discussed in depth in our GSP – Risk Permissions webinar (starts at 10:40), where roles are tailored to specific business units and user responsibilities.
For step-by-step configuration of this visibility, see the “Risk Preparing and Approving” section in the Risk Approval documentation — it details how approval status (Draft, Submitted, Resubmitted, Rejected) affects what different users can see based on their role.

Advanced Tips & Tricks: Use Cases with Setup Instructions

1. Field-Wise Permissions

Restrict access to specific fields even if the user can see the full record.
Use Case: Amanda (Risk Manager) should not edit the “Active Status” or “Risk Appetite Benchmark”.

How to Configure:

  • Go to: Administration > Role Management
  • Edit the relevant role (e.g., Risk Manager)
  • In the permission matrix, untick “Edit” for specific fields like “Active Status”
  • Assign this role to Amanda in Staff Management

See how Amanda’s field-level access is restricted in this webinar clip (15:50 – 16:50), ensuring she cannot modify specific risk fields.

To explore field-level configurations, confidentiality access, and visibility permissions by risk stage, refer to Section 3 (Risk – Flex Permissions) and Section 2 (Risk – Static Permissions) of the Release Note for a comprehensive breakdown.

2. Confidential Risk Visibility

Use Case: Michelle Jones (Project Coordinator) manages emerging risks in EMEA, which are confidential.

How to Configure:

  • Navigate to: Field Configuration > Risk Type > Enable Confidentiality
  • Go to: Role Management and create a new role: “Emerging Risk Confidential”
  • Assign this role to Michelle with access to the EMEA hierarchy
  • In Risk Settings > Standard Roles, ensure “Confidential Risk Owner” is enabled

Curious how confidential risks are set up for specific roles? Watch the Michelle Jones use case (17:30 – 20:00) in the webinar.

3. Show Pre-Approved Risks (Drafts, Rejected, Resubmitted)

Use Case: Adam Hunt (Risk Portfolio Manager) needs visibility into draft risks for operational planning.

How to Configure:

  • Go to: Role Management > Strategic Risk > Show Risk Prior to Approved Stage
  • Enable this permission for Adam’s assigned role
  • Save and refresh – he will now see risks in draft or resubmitted status

To enable pre-approved risk visibility like Adam Hunt’s scenario, see this practical demo (20:30 – 23:30) in the session.
For a detailed explanation of how preparers and approvers interact with these stages, refer to the “Risk Preparing and Approving” section in the GSP – Risk Approval guide.

How Riskonnect Can Help

Permissions are only powerful if they are set up well – and maintained. Riskonnect supports you with:

  • Initial Setup Guidance: We help you design your hierarchy-based roles to reflect your org structure.
  • Workshops and Training: Learn how to confidently assign, update, and monitor permissions.
  • Best Practice Templates: Reduce guesswork with prebuilt role configurations based on industry needs.
  • Ongoing Support: Got a unique use case? Our consultants will work with you to implement scalable solutions that flex as your organisation grows.

Whether you are refining your existing structure or setting up for the first time, we can help you build a more secure, streamlined, and compliant risk environment.

Need more hands-on detail? The Risk Permissions and Staff Management Release Note includes comprehensive tables, permission flags, and real-world conditions to support your implementation.

Configure Smart, Operate Securely

Your risk framework is only as strong as the access controls behind it. With GSP – Risk’s dual permission system – from standard responsibilities to flexible role management – you have the tools to build a governance model that fits like a glove.

So, take the time to configure it properly. Your future audits, stakeholders, and regulators will thank you.

GSP - Risk
Unraveling of GSP – Risk Permission Competencies
Understanding and managing user permissions effectively is crucial for optimising your organisation’s risk management framework...
Watch Now
How to Configure GSP – Risk Permissions: A Practical Guide for Smarter Access Control
Theja Siriwardena
Senior Business Analyst
How to Configure GSP – Risk Permissions: A Practical Guide for Smarter Access Control
How to Configure GSP – Risk Permissions: A Practical Guide for Smarter Access Control
Get In Touch
Our team is ready and available to support you with any inquiry you may have.
Contact Support
How to Configure GSP – Risk Permissions: A Practical Guide for Smarter Access Control