Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Probo Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Permissions and Integrations

Control who can read and manage Compliance Portals, connect access notifications to Slack, and automate portal workflows through OAuth, CLI, MCP, or n8n.

View as Markdown

Compliance Portal administration follows the person’s organization role and the organization boundary.

  • Owners and admins have full Compliance Portal management access for their organization. They can create, update, activate, and delete portals; manage published content and access; send updates; and configure custom domains.
  • Viewers have read-only access to portal settings, visitor access, files, references, commitments, frameworks, custom links, and domains.
  • Managed domains cannot be deleted through the custom-domain delete permission.
  • Auditor and employee roles do not receive the Compliance Portal management policies.

Use the least-privileged role that fits the person’s work. See Roles and permissions for organization-wide role guidance.

The portal overview can connect a Slack workspace and select a channel for Compliance Portal access-request notifications. Connecting or changing the channel requires permission to initiate connectors. A connection without a selected channel is shown as not configured.

OAuth clients can request one of two Compliance Portal scopes:

  • v1:compliance-page:read grants portal read operations, including lists of access records, files, references, mailing-list updates and subscribers, frameworks, links, domains, and commitments.
  • v1:compliance-page adds create, update, delete, access-management, mailing-list, domain, and publishing operations.

The caller must still be authorized for the target organization. Keep credentials out of workflows and grant write access only where an automation must change portal state.

Use the supported interface for the job:

Rights-request automation is documented separately in the CLI, MCP privacy catalog, and n8n references.

To notify another system when a portal visitor creates or changes a rights request, subscribe to the corresponding webhook events.