Skip to main content

Role Reference

The complete set of predefined roles and the permissions each one grants. For what the permissions mean, see the Permissions Overview; to change them, see Managing Roles and Permissions.

These are starting points, not fixed presets

Every predefined role can be renamed, re-described, and re-permissioned to match how your organization actually works. The matrix below is what CertHub creates during setup.

If your organization was created before 17 August 2026, your roles were instead granted all six permissions, and this matrix describes what they should look like rather than what they currently do. See Existing and new organizations.

Permission matrix​

RoleReadEdit/UpdateDownloadApproveCreate newDeleteCan manage roles
Admin✓✓✓✓✓✓✓
PRRC-ReportingObligations✓✓✓✓✓✓—
ProjectLeader✓✓✓✓✓——
RiskManager✓✓✓✓✓——
SMEforRegulatoryAffairs✓✓✓✓✓——
SMEQualityManagement✓✓✓✓✓——
ManagementRepresantative(QMB)✓—✓✓—✓—
ExecutiveManagement✓—✓✓———
CaseManager✓✓✓—✓——
ClinicalEvaluator✓✓✓—✓——
ProductManager✓✓✓—✓——
SMEforClinicalAffairs✓✓✓—✓——
SMEforComplaintHandling✓✓✓—✓——
SMEforDevelopment✓✓✓—✓——
SMEforPatentAffairs✓✓✓—✓——
SMEforProcurement✓✓✓—✓——
SMEforProduction✓✓✓—✓——

Reading the matrix, the predefined roles fall into four groups:

  • Full access — Admin and PRRC-ReportingObligations hold all six permissions. Only Admin can additionally manage roles.
  • Author and approve — ProjectLeader, RiskManager, SMEforRegulatoryAffairs, and SMEQualityManagement can create, edit, and approve, but not delete.
  • Oversight without authoring — ExecutiveManagement and ManagementRepresantative(QMB) can read, download, and approve, but cannot create or edit. These roles review work rather than produce it.
  • Author without approving — the remaining subject matter expert roles, plus CaseManager, ClinicalEvaluator, and ProductManager, can create and edit but not approve, so their work requires sign-off from one of the approving roles.

Notes on specific roles​

Three entries in the matrix look like mistakes and are not.

ManagementRepresantative(QMB) is spelled that way in the product. The role name contains a misspelling of "Representative", and CertHub keeps it because it is the stored name in every existing organization; renaming it would break anything referencing the string. Search for it as it appears in the matrix.

ManagementRepresantative(QMB) can delete but cannot edit or create. This combination is intentional. The role exists to oversee the quality management system, which includes removing content that should not be there, without authoring content itself.

PRRC-ReportingObligations has the same permissions as Admin, apart from role management. The Person Responsible for Regulatory Compliance needs unrestricted access to regulatory content, so the role is deliberately as permissive as Admin over content while holding no administrative rights over roles and users.

Role descriptions​

The regulatory function each predefined role represents.

RoleFunction
AdminSystem administrator with full access to configure and manage access control. Responsible for user management, role assignments, and system configuration.
ExecutiveManagementTop management responsible for quality policy, objectives, and customer focus. Provides leadership and commitment to the quality management system, ensures adequate resources, and promotes continual improvement.
ManagementRepresantative(QMB)Management Representative and Quality Management Board member, responsible for ensuring the quality management system is established, implemented, and maintained. Reports to top management on QMS performance and promotes awareness of regulatory requirements.
PRRC-ReportingObligationsPerson Responsible for Regulatory Compliance. Ensures regulatory compliance and fulfils reporting obligations to competent authorities, maintains regulatory compliance documentation, and oversees regulatory reporting.
ProjectLeaderLeads project teams and ensures project objectives are met. Coordinates cross-functional activities, manages timelines, and ensures compliance with quality management system procedures.
ProductManagerResponsible for product planning, development, and lifecycle management. Manages product requirements and specifications, and ensures the product meets its intended use and regulatory requirements.
RiskManagerResponsible for risk management activities: risk analysis, evaluation, and control, and monitoring risk management throughout the product lifecycle.
ClinicalEvaluatorConducts systematic and planned clinical evaluation to demonstrate conformity with general safety and performance requirements. Reviews clinical data, conducts literature searches, and prepares clinical evaluation reports.
CaseManagerManages individual cases, investigations, and corrective actions. Coordinates case activities, tracks progress, and ensures timely completion of corrective and preventive actions.
SMEQualityManagementSubject Matter Expert for quality management system activities: quality planning, control, assurance, and continual improvement.
SMEforRegulatoryAffairsSubject Matter Expert for regulatory affairs. Manages regulatory submissions and communications with regulatory authorities, and maintains regulatory intelligence.
SMEforClinicalAffairsSubject Matter Expert for clinical affairs: clinical evaluation, clinical investigations, and post-market clinical follow-up.
SMEforComplaintHandlingSubject Matter Expert for complaint handling and post-market surveillance. Manages complaint investigation, corrective actions, and post-market surveillance.
SMEforDevelopmentSubject Matter Expert for product development. Provides technical expertise in design and development, and ensures design controls meet regulatory requirements.
SMEforProductionSubject Matter Expert for production and manufacturing. Ensures production processes are controlled and meet quality requirements.
SMEforProcurementSubject Matter Expert for procurement and supplier management. Ensures suppliers meet quality requirements, and manages supplier qualification and monitoring.
SMEforPatentAffairsSubject Matter Expert for intellectual property and patent matters. Ensures protection of intellectual property while maintaining regulatory compliance and supporting innovation.

Changes from earlier role lists​

Earlier versions of CertHub offered three roles — Admin, ExecutiveManagement, and ManagementRepresentative(QMR) — which described access level only and carried no configurable permissions.

That list is superseded by the matrix above. Two differences to be aware of when following older documentation or internal procedures:

  • ManagementRepresentative(QMR) is now ManagementRepresantative(QMB), and its permissions are explicit rather than implied.
  • Admin and ExecutiveManagement continue to exist, but their capabilities are now defined by the permissions in the matrix and can be changed, rather than being fixed access levels.