Role Reference
The complete set of predefined roles and the permissions each one grants. For what the permissions mean, see the Permissions Overview; to change them, see Managing Roles and Permissions.
Every predefined role can be renamed, re-described, and re-permissioned to match how your organization actually works. The matrix below is what CertHub creates during setup.
If your organization was created before 17 August 2026, your roles were instead granted all six permissions, and this matrix describes what they should look like rather than what they currently do. See Existing and new organizations.
Permission matrix
| Role | Read | Edit/Update | Download | Approve | Create new | Delete | Can manage roles |
|---|---|---|---|---|---|---|---|
| Admin | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| PRRC-ReportingObligations | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| ProjectLeader | ✓ | ✓ | ✓ | ✓ | ✓ | — | — |
| RiskManager | ✓ | ✓ | ✓ | ✓ | ✓ | — | — |
| SMEforRegulatoryAffairs | ✓ | ✓ | ✓ | ✓ | ✓ | — | — |
| SMEQualityManagement | ✓ | ✓ | ✓ | ✓ | ✓ | — | — |
| ManagementRepresantative(QMB) | ✓ | — | ✓ | ✓ | — | ✓ | — |
| ExecutiveManagement | ✓ | — | ✓ | ✓ | — | — | — |
| CaseManager | ✓ | ✓ | ✓ | — | ✓ | — | — |
| ClinicalEvaluator | ✓ | ✓ | ✓ | — | ✓ | — | — |
| ProductManager | ✓ | ✓ | ✓ | — | ✓ | — | — |
| SMEforClinicalAffairs | ✓ | ✓ | ✓ | — | ✓ | — | — |
| SMEforComplaintHandling | ✓ | ✓ | ✓ | — | ✓ | — | — |
| SMEforDevelopment | ✓ | ✓ | ✓ | — | ✓ | — | — |
| SMEforPatentAffairs | ✓ | ✓ | ✓ | — | ✓ | — | — |
| SMEforProcurement | ✓ | ✓ | ✓ | — | ✓ | — | — |
| SMEforProduction | ✓ | ✓ | ✓ | — | ✓ | — | — |
Reading the matrix, the predefined roles fall into four groups:
- Full access — Admin and PRRC-ReportingObligations hold all six permissions. Only Admin can additionally manage roles.
- Author and approve — ProjectLeader, RiskManager, SMEforRegulatoryAffairs, and SMEQualityManagement can create, edit, and approve, but not delete.
- Oversight without authoring — ExecutiveManagement and ManagementRepresantative(QMB) can read, download, and approve, but cannot create or edit. These roles review work rather than produce it.
- Author without approving — the remaining subject matter expert roles, plus CaseManager, ClinicalEvaluator, and ProductManager, can create and edit but not approve, so their work requires sign-off from one of the approving roles.
Notes on specific roles
Three entries in the matrix look like mistakes and are not.
ManagementRepresantative(QMB) is spelled that way in the product. The role name contains a misspelling of "Representative", and CertHub keeps it because it is the stored name in every existing organization; renaming it would break anything referencing the string. Search for it as it appears in the matrix.
ManagementRepresantative(QMB) can delete but cannot edit or create. This combination is intentional. The role exists to oversee the quality management system, which includes removing content that should not be there, without authoring content itself.
PRRC-ReportingObligations has the same permissions as Admin, apart from role management. The Person Responsible for Regulatory Compliance needs unrestricted access to regulatory content, so the role is deliberately as permissive as Admin over content while holding no administrative rights over roles and users.
Role descriptions
The regulatory function each predefined role represents.
| Role | Function |
|---|---|
| Admin | System administrator with full access to configure and manage access control. Responsible for user management, role assignments, and system configuration. |
| ExecutiveManagement | Top management responsible for quality policy, objectives, and customer focus. Provides leadership and commitment to the quality management system, ensures adequate resources, and promotes continual improvement. |
| ManagementRepresantative(QMB) | Management Representative and Quality Management Board member, responsible for ensuring the quality management system is established, implemented, and maintained. Reports to top management on QMS performance and promotes awareness of regulatory requirements. |
| PRRC-ReportingObligations | Person Responsible for Regulatory Compliance. Ensures regulatory compliance and fulfils reporting obligations to competent authorities, maintains regulatory compliance documentation, and oversees regulatory reporting. |
| ProjectLeader | Leads project teams and ensures project objectives are met. Coordinates cross-functional activities, manages timelines, and ensures compliance with quality management system procedures. |
| ProductManager | Responsible for product planning, development, and lifecycle management. Manages product requirements and specifications, and ensures the product meets its intended use and regulatory requirements. |
| RiskManager | Responsible for risk management activities: risk analysis, evaluation, and control, and monitoring risk management throughout the product lifecycle. |
| ClinicalEvaluator | Conducts systematic and planned clinical evaluation to demonstrate conformity with general safety and performance requirements. Reviews clinical data, conducts literature searches, and prepares clinical evaluation reports. |
| CaseManager | Manages individual cases, investigations, and corrective actions. Coordinates case activities, tracks progress, and ensures timely completion of corrective and preventive actions. |
| SMEQualityManagement | Subject Matter Expert for quality management system activities: quality planning, control, assurance, and continual improvement. |
| SMEforRegulatoryAffairs | Subject Matter Expert for regulatory affairs. Manages regulatory submissions and communications with regulatory authorities, and maintains regulatory intelligence. |
| SMEforClinicalAffairs | Subject Matter Expert for clinical affairs: clinical evaluation, clinical investigations, and post-market clinical follow-up. |
| SMEforComplaintHandling | Subject Matter Expert for complaint handling and post-market surveillance. Manages complaint investigation, corrective actions, and post-market surveillance. |
| SMEforDevelopment | Subject Matter Expert for product development. Provides technical expertise in design and development, and ensures design controls meet regulatory requirements. |
| SMEforProduction | Subject Matter Expert for production and manufacturing. Ensures production processes are controlled and meet quality requirements. |
| SMEforProcurement | Subject Matter Expert for procurement and supplier management. Ensures suppliers meet quality requirements, and manages supplier qualification and monitoring. |
| SMEforPatentAffairs | Subject Matter Expert for intellectual property and patent matters. Ensures protection of intellectual property while maintaining regulatory compliance and supporting innovation. |
Changes from earlier role lists
Earlier versions of CertHub offered three roles — Admin, ExecutiveManagement, and ManagementRepresentative(QMR) — which described access level only and carried no configurable permissions.
That list is superseded by the matrix above. Two differences to be aware of when following older documentation or internal procedures:
- ManagementRepresentative(QMR) is now ManagementRepresantative(QMB), and its permissions are explicit rather than implied.
- Admin and ExecutiveManagement continue to exist, but their capabilities are now defined by the permissions in the matrix and can be changed, rather than being fixed access levels.