Getting started

Invite your team

Add members, assign admin, editor, or viewer roles, and manage pending invitations.

RolesAdminRoute/settings?tab=membersShown toAll organizations

What it is

Members are the people who can sign in to your organization. Each has one role, admin, editor, or viewer, which decides what the app lets them change. Invitations go out by email; until they are accepted they sit in a pending list you can cancel from. A compliance program needs more than one pair of hands, so this is usually the first thing to do after the wizard: control owners need write access, and auditors or leadership often want read-only access.

Where to find it

SettingsMembers

Only admins can open Settings. The tab has two cards: Active Members with columns Name, Email, Role, Joined, and Actions, and Pending Invitations with Email, Invited, and Actions.

The Active Members card listing members with role selects, and the Pending Invitations card belowThe Active Members card listing members with role selects, and the Pending Invitations card below
Members and pending invitations.

Key actions

Invite a member

Click Invite Member in the Active Members card.
Enter the Email Address. The placeholder suggests an address at your own domain.
Choose a Role. The dialog defaults to Viewer, so change it for anyone who will own controls or edit policies.
Click Send Invitation. The toast "Invitation sent!" confirms it, and the address appears under Pending Invitations.
The Invite Member dialog with an Email Address field and a Role selectThe Invite Member dialog with an Email Address field and a Role select
The invite dialog. Each role option shows its description.

The same invitation can be sent from two other places: the Invite your IT admin card in the organization wizard opens Invite Your IT Admin, and the welcome guide's Invite team member button opens Invite Team Member with an optional message. All three create the same kind of invitation.

Decide who gets which role

PersonSuggested roleWhy
Whoever runs the programAdminNeeds Settings, Frameworks, Members, and billing
IT or platform adminEditorConnects data sources and owns technical controls without needing settings
Control and policy ownersEditorSet statuses, link evidence, edit and approve policies
Leadership, auditors, advisorsViewerSee everything, change nothing

Keep at least two admins. Noru blocks removing the last one, but it cannot help when that person leaves the company.

Cancel a pending invitation

In Pending Invitations, use the action on the row. The toast "Invitation cancelled" confirms it. Send a fresh invitation if the email went to the wrong address.

Change a role or remove a member

Use the role select in the Actions column to change a role, and the remove action to take someone out of the organization. Removing ends their access immediately. Both actions are refused for the last admin: the app shows "Cannot remove the last admin of the organization", and the server independently rejects "Cannot change the role of the last admin of the organization". The role select is disabled while the organization has only one member.

Statuses and fields

StatusMeaningSet by
AdminadminFull access to all organization features and settingsThe invite, or an admin later
EditoreditorCan manage content and workflows, limited settings accessThe invite, or an admin later
ViewerviewerRead-only access to organization dataThe invite, or an admin later
CapabilityAdminEditorViewer
Read every pageYesYesYes
Create and edit records, set statuses, link evidenceYesYesNo
Open Settings and manage frameworks, members, securityYesNoNo
Billing checkoutYesYesNo

Viewers see the text Read-only access in place of bulk action buttons on the controls, evidence, and assets pages.

Membership is not personnel

MembersPersonnel directory
WhereSettings → MembersPersonnel → Directory
WhoPeople with a Noru loginEveryone your program covers, synced from identity providers and HR
Used forAccess and permissionsMFA coverage, training, policy acknowledgement
Created byAn invitationA data source sync or a manual entry

Inviting someone does not add them to the directory, and a directory record does not let anyone sign in.

Tips and gotchas

Invite the IT admin before you connect data sources. Most connectors need someone with admin rights in the provider, and an editor can connect them without needing access to Settings.

Roles live in Noru

The role on the Noru membership is the only one permission checks read. Changing a member's role anywhere other than this tab does nothing in the app; change it here.

A member who accepted the invitation but has not opened the app yet still appears in Active Members. Their row looks like any other.

What Noru does not do

Noru does not sync roles back to the sign-in provider, does not read the sign-in provider's organization role at request time, and does not create a personnel record when someone joins. It does not offer per-page permissions; the three roles are the whole model.

Last updated on