Step 1 - Configure your Company Entities
Before restricting access, Formalize needs to mirror your organizational structure. If your company is made of three entities, for example, setting up those in the platform allows you to segregate data, such as keeping Entity 1's documents invisible to Entity 2's users. At the same time when there is overlap of data this can be visible and editable to both, avoiding multi versioning.
Define your entities by navigating to Settings -> Company -> Company entities and click on Add company entity.
Scroll down to Connections at the bottom of the page to link your company entities to specific Formalize modules (e.g., Suppliers, Risks). For a deeper look at how this works, check out our Connections article.
Once the connection is established, you can link individual elements within those modules to one or more of the entities using the Connections area on the element's page.
Step 2 - Configure Access Roles
Define Access Roles to dictate which actions users can do and in which conditions.
For example, create an Access Role for an external auditor to review Entity 1's Risk Register: you can create a "Viewer" role, but add a condition so they only have access to elements linked to Entity 1.
Go to Settings -> Users & access -> Access roles and click on Create.
Select the modules you want to grant access to. To learn more about permission types, check out our article about Access Roles.
For each of the permission types, you will be able to add Conditions to control exactly what a user can see. You can restrict access:
By Responsibility: Select Only access elements where user is the designated Responsible User.
By Entity: Select Only access elements linked to specific entities, then check the relevant entities.
Step 3 - Assign Access Role to Users
This is where you tie the person to the rules. Applying these targeted roles ensures that the moment a user logs in, their view is already filtered to show only what is relevant to them.
For example, when onboarding a new Risk Manager for a specific entity, assigning them a specific role instantly filters their dashboard to only show risks and incidents linked to their subsidiary, keeping sensitive data from the other entities secure.
Go to Users & Access -> Users and create the new user. See how to in our User Management article.
In the Roles drop-down menu, select the newly created entity-specific role.
To add entity-specific Access Role to an existing user, go to the Users list view, click View next to the user, and edit their access roles.
4. Visualizing the Result
To truly understand the value of this setup, it is helpful to look at how the platform adapts its interface based on the user's assigned Access Role.
Unrestricted Visibility
The Admin sees the "big picture." Their dashboard aggregates risks, resources, and insights across all entities.
Focused & Restricted Visibility
The Risk Manager for Entity 1 logs into the exact same platform, but their workspace is instantly filtered by their Access Role.
Common Questions
Can one user have different roles across multiple entities?
Yes. You can assign multiple roles to a single user. Permissions in Formalize are cumulative—a user receives the combined total of all permissions granted across all assigned roles.Can a user have different access levels for different entities?
Yes. To grant varying access levels across entities, create separate roles and assign both to the user. For example:Role A: View-only access to suppliers linked to Entity A.
Role B: View and Edit access to suppliers linked to Entity B.
Assigning both Role A and Role B to User X gives them view-only rights in Entity A and full edit rights in Entity B.
We hope this article was helpful!
If you have any additional questions, please reach out to us via chat in the bottom right corner of the page — our team is always happy to assist you further.
