5 min read ·

What is Portfolio-Based Role Access Control in Profit.co?

Portfolio-based role access control gives Super Users a dedicated way to decide what each portfolio member can see and do, independent of the organization's platform-wide roles. Members receive their access directly on the portfolio they're assigned to, and that access stays visible for review at any time.

What is Portfolio-Based Role Access Control?

A portfolio role is a named permission profile that applies only within the portfolio where it's assigned. Profit.co ships five default roles: Portfolio Owner, Portfolio Manager, Portfolio Finance Manager, Portfolio User, and Portfolio Read Only User, each carrying a fixed description and a set of effective privileges.

Each role's permissions are grouped into functional categories, including Maintain Overview, Maintain Dashboard, Maintain Roadmap, Maintain Risk, Maintain Budget Request, Maintain Funding Request, and Maintain Members & Access. Within each category, individual permissions toggle at a View or Manage level, giving a granular breakdown beneath the role's summary description.

Note

Portfolio roles apply only within the portfolio where they're assigned. They don't carry over to other portfolios and don't grant platform-wide access.

Role Description Effective Privileges
Portfolio Owner Full control of the portfolio and everything in it. All Privileges
Portfolio Manager Runs the portfolio day to day. View Portfolio, Manage Portfolio, Add Sub-Projects, Manage Weights, Manage Request, Manage Documents
Portfolio Finance Manager Manages budget, funding requests, and benefits. View Portfolio, Manage Documents, Export CSV, Export PPT, Export PDF, View Members & Access
Portfolio User Views the portfolio, raises requests, edits documents. View Portfolio, Manage Request, Manage Documents, Export CSV, Export PPT, Export PDF
Portfolio Read Only User View-only access across the portfolio. View Portfolio, Export CSV, Export PPT, Export PDF, View Dashboard, View Risk, View Strategic Alignment

Beyond these five defaults, Super Users can add further custom roles with their own permission combinations to cover additional functions or access levels the organization needs.

Why Portfolio-Based Role Access Control Matters

Portfolio-based role access control replaces one-size-fits-all permissions with scoped, function-specific access. Each benefit below reflects a concrete gap this closes for portfolio governance.

Benefit Description
Granular access per portfolio Organizations control exactly what each member can see and do inside a specific portfolio, instead of relying on one platform-wide role for every context.
Clear permission transparency Super Users and members can open any assigned role's permission breakdown directly from Members & Access and see the exact privileges in effect.
Reduced over-permissioning Purpose-built roles like Portfolio Finance Manager and Portfolio Read Only User scope access to a function, rather than granting broader privileges than a member's responsibilities require.

How It Works

Configure Portfolio Roles

Step 1

  • Navigate to Settings → Portfolios and Projects → Portfolios → Access Control
  • Check each role's description and effective privileges listed in the Portfolio Roles table

Step 2

  • Click + Create Role and select the specific permissions the new role should carry
  • Use the toggle next to a role's name to turn it on or off

Prerequisite

Only Super Users can create, configure, and enable or disable portfolio roles from the Access Control page.

View a Member's Assigned Role and Permissions

Step 1

  • Navigate to a portfolio and open the Members & Access page
  • Select a role for a member from the Portfolio Roles dropdown
  • Click View permission beneath the assigned role to see that member's full permission breakdown

Portfolio-Based Role Access Control Scenarios and Their Outcomes

Scenario What Happens
You try to disable a default portfolio role (Portfolio Owner, Portfolio Manager, Portfolio Finance Manager, Portfolio User, or Portfolio Read Only User). Profit.co blocks the action, since default roles cannot be disabled and only custom roles support the toggle.
You disable a custom portfolio role that's already assigned to one or more members. Profit.co keeps each assigned member's access unchanged, so they continue to have the permissions defined in that role.
You change a member's portfolio role from the Members & Access page. Profit.co sends the member a notification confirming their updated role assignment.

Best Practices for Portfolio-Based Role Access Control

  • Build custom roles around a single function, such as budget approvals or reporting, rather than duplicating a default role with minor edits, since default roles can't be disabled or removed once shipped.
  • Reserve Portfolio Owner for the individual accountable for the portfolio, since it carries all privileges, including sub-project creation and document management, in one assignment.
  • Confirm a role's full permission breakdown using View permission before assigning it to a new member, rather than judging scope from the role name alone.
  • Complete custom role creation in one sitting, since closing the + Create Role panel before saving discards every permission selected so far.
  • Use Portfolio Read Only User for external or occasional stakeholders who only need dashboard and export access, keeping Manage-level privileges limited to active contributors.

Frequently Asked Questions

Q1. Do portfolio roles apply across every portfolio a member belongs to?

No. Roles are assigned per portfolio from that portfolio's Members & Access page, so the same member can hold different roles in different portfolios.

Q2. Who can create or modify custom portfolio roles?

Only Super Users can create, configure, and enable or disable portfolio roles from the Access Control page.

Q3. Does a portfolio role assignment change a member's platform-wide role?

No. Portfolio roles are scoped to the specific portfolio and are separate from the organization's global roles.

Execute your strategy with confidence

Connect OKRs, tasks, and teams in one place with Profit.co

Athena

Welcome to Profit.co 👋

How can I help you today?