Enterprise access governance

Teams, roles, and approval authorities

AIM separates workspace permissions from independent decision authority across technical, procurement, security, and executive governance.

Freedom AIM eagle and gear mark

1How Organizations Work

Every AIM account belongs to an Organization. An org is the shared workspace where your team creates assessments, manages projects, and generates reports. Think of it as your agency's or company's dedicated instance of AIM.

Your enterprise agreement is attached to the organization, not to individual user accounts. It defines the capabilities and capacity available to the workspace, including:

  • SeatsLicensed named users who can log in and work within your org
  • AssessmentsThe total number of modernization assessments the organization can maintain
  • Active ProjectsThe number of implementations that can be governed concurrently
  • CapabilitiesContract-enabled modules such as Pulse, procurement artifacts, integrations, MBSE, and agent operations

You can view your org's live usage at any time from Dashboard → Team & Usage.

2Seats vs. Guest Collaborators

Org Seat Holders

Named users invited into your organization. They log in with their own AIM account, persist across all assessments, and hold an org-level role (Owner, Admin, Engineer, Program Analyst, Reviewer, or Viewer).

  • Full AIM account login
  • Access to all org assessments (per role)
  • Count against your seat quota
  • Appear in org team management

Assessment Guest Collaborators

External stakeholders (vendors, contractors, clients) invited to a single specific assessment via email. They authenticate with a one-time code and do not hold an org seat.

  • Email OTP login — no AIM account required
  • Scoped to one assessment only
  • Do not consume org seats
  • Access tracked in the assessment audit log
  • Cannot create or manage anything

Only Owners and Admins can invite guest collaborators. Guest limits are set by your organization contract — see Contract & Entitlements.

3Organization Roles

Owner

Accountable organization owner with contract, seat, configuration, and workflow oversight. May not approve or release their own artifact unless a recorded single-user exception applies.

Federal: CIO / PEO · Healthcare: CIO / CMO · Education: CIO / Superintendent · Enterprise: CTO

Can Do

  • Create, edit, archive, and permanently delete assessments
  • Invite, manage, and remove all org members
  • Manage the organization contract and enabled capabilities
  • View org-wide activity and audit logs
  • Invite and revoke assessment guest collaborators
  • Generate and export all document types
  • Use Document Translator — initiate, edit, and finalize
  • Configure org settings
  • Activate Pulse Sustainment Mode for any completed Pulse implementation
  • Configure CCB membership and voting thresholds
  • View and export Pulse Sustainment reports
  • Manage Pulse Sustainment notification policy
Admin

Operational administrator with full platform and organization-management access. May not approve or release their own artifact unless a recorded single-user exception applies.

Federal: Deputy CIO / IT Director · Healthcare: IT Director · Education: Deputy Superintendent · Enterprise: Engineering Director

Can Do

  • Create, edit, and archive assessments
  • Invite and manage org members (cannot remove Owner)
  • View org-wide activity and audit logs
  • Invite and revoke assessment guest collaborators
  • Generate and export all document types
  • Use Document Translator — initiate, edit, and finalize
  • Activate Pulse Sustainment Mode for any completed Pulse implementation
  • Configure CCB membership and voting thresholds
  • View and export Pulse Sustainment reports

Cannot Do

  • Change the organization contract or entitlements
  • Delete the organization
Engineer

Technical operator who captures evidence, runs AIM engines, produces technical reports, and submits acquisition-ready handoffs. Cannot author procurement documents, approve documents, or release acquisition artifacts.

Federal: Systems Engineer / IT Architect · Healthcare: Clinical Systems Engineer · Education: Infrastructure Lead · Enterprise: Solutions Architect

Can Do

  • Create new assessments and manage system inventory
  • Run all analysis engines (RAO scoring, constraint normalization, risk calculation, architecture diagrams)
  • Generate technical reports: White Paper, Modernization Report
  • View org members list
  • Submit change requests to the Change Control Board (CCB)
  • Log technical configuration changes against the as-built baseline
  • Respond to drift alerts with remediation notes

Cannot Do

  • Generate procurement documents (RFP, IGCE, Market Research, Acquisition Strategy) — requires Program Analyst
  • Use Document Translator — requires Program Analyst
  • Invite or remove org members
  • Invite assessment guest collaborators
  • Approve or flag documents in the review queue
  • View activity logs or audit trails
  • Change organization contract entitlements
Program Analyst

Acquisition operator who accepts technical handoffs and converts verified inputs into procurement drafts. Cannot create assessments, run technical engines, or approve/release their own documents.

Federal: Program Manager / COR · State/Local: Procurement Officer · Healthcare: IT Project Manager · Education: Purchasing Coordinator · Enterprise: Business Analyst

Can Do

  • Generate procurement documents: RFP, IGCE, Market Research Report, Acquisition Strategy
  • Use Document Translator — upload agency templates, fill fields, edit and finalize translated documents
  • View all assessments and their outputs
  • Export previously generated PDFs and documents
  • Maintain the post-award procurement action register
  • Log procurement actions against the original IGCE for variance tracking
  • Receive procurement variance alerts

Cannot Do

  • Create or edit assessments
  • Run technical analysis engines (RAO scoring, constraint normalization, architecture diagrams)
  • Generate technical reports (Modernization Report, White Paper)
  • Invite or remove org members
  • Invite assessment guest collaborators
  • Approve or flag documents in the review queue
  • View activity logs or change contract entitlements
Reviewer

Independent reviewer who approves or returns immutable artifact versions and records release authority. Cannot author assessments or documents, run engines, or attest Pulse/PSM milestones.

Federal: Legal Counsel / Independent Reviewer · Healthcare: Compliance Officer · Education: Academic Affairs · Enterprise: QA Lead / Change Advisory Board

Can Do

  • View all assessments and their outputs
  • Access the org-wide document review queue
  • Approve or flag generated reports, procurement docs, and translated documents
  • Vote on Pulse Sustainment Change Requests when included in a CCB slate
  • Attest Change Request closeouts (sign off that the change was actually delivered)
  • Export previously generated PDFs
  • Vote via email reply for CCB requests (no login required)
  • Receive CCB voting reminders and decision summaries

Cannot Do

  • Create or edit assessments
  • Run analysis engines or generate any documents
  • Use the Document Translator
  • Be named Designated or Backup Lead on a Pulse or PSM record
  • Attest Pulse or PSM milestone completions (Lead-only)
  • Invite or remove org members
  • Invite assessment guest collaborators
  • View activity logs or change contract entitlements
Viewer

Read-only stakeholder for assessments, reports, and implementation status. Cannot create, edit, generate, approve, or release content.

Federal: Congressional Liaison / Oversight Staff · Healthcare: Department Director · Education: Faculty Lead / Board Member · Enterprise: Product Manager

Can Do

  • View all assessments and their results
  • Read existing reports and recommendations
  • Monitor the Pulse implementation dashboard
  • Export previously generated PDFs
  • View the Pulse Sustainment dashboard
  • Receive quarterly stakeholder digest emails (opt-in)
  • View drift reports and compliance posture (read-only)

Cannot Do

  • Create or edit assessments
  • Run analysis engines
  • Generate new documents or use the Translator
  • Approve or flag documents
  • Invite collaborators of any kind
  • View activity logs

3AApproval Authorities

Approval authorities are not additional access roles. They are accountable decision designations layered over a member’s Owner, Admin, Engineer, Program Analyst, Reviewer, or Viewer role. This preserves separation of duties and lets AIM record who may decide each governance lane without pretending that software grants legal authority.

Procurement Approval Authority

Provides the independent budget and acquisition decision after the Program Analyst prepares and routes the procurement package.

Responsibilities

  • Review the business case, independent cost estimate, funding position, and acquisition package.
  • Approve, return, or decline the exact submitted package version with a recorded rationale.
  • Confirm that required fiscal, legal, competition, and procurement reviews are complete.

Boundary: An AIM designation records workflow responsibility; it does not create contracting, fiscal, or warrant authority. The organization must separately verify the person’s real delegation and limits.

Common titles: Approving Official, Budget Authority, Contracting Officer, Procurement Director, or equivalent.

System Authorizing Official

Owns the formal decision on whether architecture, cybersecurity, privacy, and operational risk are acceptable for the system to proceed.

Responsibilities

  • Review the target architecture, security evidence, residual risks, exceptions, and operating conditions.
  • Approve, conditionally approve, return, or decline the exact system baseline submitted for authorization.
  • Record accepted risk, required conditions, authorization duration, and reassessment triggers.

Boundary: A delegate may coordinate review and make recommendations, but may accept risk or sign the final authorization only when the organization has explicitly vested that authority.

Common titles: Authorizing Official, Designated Authorizing Official, Risk Executive, Security Authorizing Executive, or authorized delegate.

Executive Technology Sponsor

Provides leadership approval that the final design and delivery plan align with strategy, operating priorities, investment intent, and accountable ownership.

Responsibilities

  • Review the recommended design, roadmap, material tradeoffs, expected outcomes, and organizational readiness.
  • Confirm executive sponsorship, accountable ownership, and alignment with technology strategy.
  • Approve, return, or decline the exact design and build baseline submitted for leadership decision.

Boundary: This designation does not replace procurement approval or formal security risk authorization. Its displayed title can be configured to match the organization.

Common titles: CTO, CIO, Chief Architect, VP Technology, Executive Design Authority, or equivalent.

4Permissions at a Glance

ActionOwnerAdminEngineerProg. AnalystReviewerViewer
Create & edit assessments
Manage system inventory
Run technical analysis engines
Generate White Paper
Generate Modernization Report
Generate RFP
Generate IGCE
Generate Market Research Report
Generate Acquisition Strategy
Use Document Translator
Review & approve documents
Be named Pulse / PSM Designated Lead
Attest Pulse / PSM milestones (Lead-only for Engineers)
Activate Pulse Sustainment Mode
Configure CCB membership
Submit change requests
Vote on CCB change requests
Attest Change Request closeouts
Log configuration changes
Log procurement actions
View Pulse Sustainment dashboard
Export Pulse Sustainment reports
Export PDFs (existing documents)
Invite org members
Remove org members
Invite guest collaborators
View activity & audit logs
View contract & entitlements
Delete organization

5Activity & Audit Logs

Org-Wide Activity Log

Available to Owners and Admins when enabled for the organization at Dashboard → Team → Activity Log. Shows a timeline of all org-level events:

  • User invitations sent and accepted
  • Assessments created
  • Guest collaborator invite and access events

Assessment-Level Access Log

Inside any assessment, Owners and Admins can open the Collaborators panel and switch to the Access Log tab to see:

  • Who was invited (guest email, role)
  • Email verification events (pass/fail)
  • Session start timestamps and IP addresses
  • Access revocations

6Contract Capacity & Capabilities

FeatureOrganization agreementEntitlement recordRuntime enforcement
Named usersCapacity agreedMaximum usersOrganization membership
AssessmentsCapacity agreedAssessment limitRole + contract
Active projectsCapacity agreedProject limitRole + contract
Guest collaboratorsCapacity agreedGuest limitScoped invitation
Platform capabilitiesModules agreedCapability flagsServer + data boundary

Capacity and enabled modules are defined by the organization agreement. Request enterprise access.

7Pulse Sustainment Mode (PSM)

When a modernization implementation is complete, Pulse Sustainment Mode (PSM) activates to track the system through its operational life — change board decisions, configuration drift, procurement renewals against the original IGCE, and compliance posture over time.

PSM uses the same six-role model. The Reviewer role is the natural fit for Change Control Board (CCB) voting members — Reviewers attest CCB decisions through the same workflow they already use for Pulse implementation milestones. Reviewers can also vote directly from email without logging in, which makes CCB participation practical for executive Reviewers (CIO, CISO, Chief Compliance Officer) who do not need to live inside a SaaS dashboard to do their CCB job.

PSM is included with organization contracts when the Pulse Sustainment capability is enabled. Your Owner or Admin can review the organization's current capabilities under Contract & Entitlements.

Segment-aware terminology

  • Federal: Configuration Control Board (CCB)
  • Healthcare: Change Advisory Board (CAB)
  • Commercial & Education: Change Management
  • Financial: Change Control

Same engine, segment-appropriate labels. AIM determines which terminology to use from your organization's sector setting.

8Common Questions

Can a Viewer generate a report?

No. Viewers can read existing reports and export previously generated PDFs, but they cannot trigger new report generation, run analysis engines, or modify any assessment data.

Can an Engineer or Program Analyst invite a guest collaborator to their assessment?

No. Only Owners and Admins can invite or revoke guest collaborators. Engineers create and edit assessments; Program Analysts consume accepted technical handoffs to prepare procurement drafts. External access management requires an elevated role.

Can someone be a Viewer in the org but a collaborator on a specific assessment?

Yes. Org roles and assessment guest collaborators are separate concepts. An org Viewer has read-only access to all assessments as a seat holder. A guest collaborator has email-OTP access to a single assessment but does not hold a seat. The same person could technically be both.

How does guest collaborator authentication work?

When an Owner or Admin invites a guest, AIM sends a secure invite link to the email provided. When the guest opens the link, they receive a one-time passcode (OTP) to verify their identity. Sessions are time-limited and revocable at any time. All access events are logged in the assessment audit trail.

What happens when a guest invite expires?

Pending guest invites expire automatically after the configured window (default 7 days). The daily cleanup job marks expired invites and logs an expiry event in the audit trail. Guests with expired invites must be re-invited to regain access.

Who can change a member's role?

Owners can change any member role including other Admins. Admins can change the role of Engineers, Program Analysts, Reviewers, and Viewers but cannot modify the Owner role.

Does Pulse Sustainment Mode cost extra?

Pulse Sustainment Mode (PSM) is available when enabled in the organization agreement. Future agent operations will remain a separate, explicitly governed capability.

Can a Reviewer vote on a CCB change request without logging in?

Yes. Reviewers receive an email when a vote is required and can reply directly with their vote (approve / defer / reject) and rationale. AIM parses the reply, attests the vote cryptographically, and logs it to the audit trail. This makes CCB participation practical for executive Reviewers (CIO, CISO, Chief Compliance Officer, Compliance Officer) who do not need to live inside a SaaS dashboard to do their CCB job.

What happens to the implementation Pulse when sustainment activates?

The implementation Pulse is frozen and becomes the canonical "as-built" baseline that PSM tracks drift against. It remains viewable in read-only mode forever — it does not disappear, it becomes the source of truth for what was originally delivered.

Ready to set up your team?

Freedom AIM - Architectural Insight for Modernization