Who can do what in Smartbox
Smartbox uses role-based access: every person you invite is given a role, and their role decides what they can see and do. This keeps sensitive review work in the right hands while still letting your team collaborate. Roles are assigned per user within your account, and access is always checked by the server, so a person only ever gets the actions their role allows.
This article explains the roles in customer terms and how access is kept separate between organisations. For how signing in and multi-factor authentication work, see Signing in and MFA; for the bigger picture, see Keeping your data secure.
The main roles
Administrator
Administrators look after the account itself. Broadly, an administrator can invite and manage users and their roles, manage company settings and branding, and configure the account-level options that shape everyone's work — for example the categories and term/pattern lists your organisation uses. An administrator can also help a colleague who has lost access to their authenticator app by resetting their MFA so they can enrol a new device.
Standard
Standard users do the day-to-day review work: creating and working in Boxes, uploading documents, reviewing detected sensitive data, culling, redacting, and running Workflows — within the permissions they have been given. Standard users do not manage the account or other people's access.
Specialist roles
Alongside administrator and standard, Smartbox offers specialist roles for teams that want access aligned to particular responsibilities. Your administrator assigns these where they fit your organisation's way of working. If you are unsure which role a colleague should have, an administrator can review and adjust it at any time.
Not sure who your administrator is? Anyone with the administrator role can see and manage users in your company settings — ask a colleague on the team, or contact Customer Success.
Access at the Box level
Roles set what someone can do across the account, but individual Boxes add another layer of control. When a Box is created with the Advanced option, you can choose its sharing and download permissions (as well as which categories and lists apply, and per-box page caps). This lets you keep a particularly sensitive matter tightly held, or open a Box up to a wider group, without changing anyone's overall role. See Creating a Box for the full set of Advanced options.
Account isolation
Smartbox is multi-tenant, which means each customer's account is fully isolated. Your users, Boxes, documents and records belong to your account alone. There is no way to switch between accounts: a person signs in to one organisation's account, and requests for anything outside it simply return a "not found" result, as though it does not exist. This separation is enforced by the server, not just hidden in the interface.
Because accounts are isolated, a user who needs to work in a different organisation's Smartbox account must be invited there as a separate user. There is no tenant-switching for a single person.
Access through the API
If your organisation uses the Smartbox API, access is granted through scoped access tokens issued per account. Each token is limited to specific permissions, so you can give an integration only the access it needs. Treat tokens like passwords: keep them secret and share them no more widely than an integration requires. See Using the API for details.
Keeping a record
Many actions in Smartbox are written to an audit trail that records who did what and when. This helps administrators understand how a Box or record reached its current state and supports defensible, accountable review.
FAQ
Can a standard user be made an administrator?
Yes. An administrator can change a user's role at any time in company settings.
A colleague has lost their phone and can't sign in. What do we do?
An administrator can reset that user's MFA so they can enrol a new authenticator app. See Signing in and MFA.
Can I limit who opens or downloads from a particular Box?
Yes. Create the Box with the Advanced option and set its sharing and download permissions to match how sensitive the matter is.
Can one login work across two of our organisation's accounts?
No. Accounts are isolated and there is no tenant-switching. Each account needs its own user invitation.
For formal security assurances beyond what is described here, please contact Customer Success.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article