Roles and Permissions
Brainstorme enforces role-based access so users can only perform actions appropriate to their assignment. Roles are granted per study — the same person can be an Admin on one study and an Uploader on another, and they see a different portal in each.
The roles
These are the roles an administrator can assign from the study's Users page. See Inviting Users for how to grant one.
| Role | What it is for |
|---|---|
| Admin | Runs the study. Every action on this page, including settings, exports, users, and the audit log. |
| Reader | Reads imaging and writes reports. Opens studies in the viewer, completes and e-signs reader reports, and downloads exports. |
| Uploader | Submits imaging. Creates subjects and uploads studies, but never reads or reports on them. |
| CRA | Monitors sites. Sees the study's data and brings uploaders onto their own sites — no other role, no other site. |
| Sponsor | Study oversight. Sees data and manages who has access, but does not upload imaging or write reports. |
| Billing | Organization billing only. Invoices and usage — no access to imaging, subjects, or reports. |
Brainstorme support staff hold an additional internal role that cannot be assigned from the Users page. It is not covered here.
What each role can do
Every action the portal offers, and who can complete it. Where an action has a guide, the action links to it.
| Action | Admin | Reader | Uploader | CRA | Billing | Sponsor |
|---|---|---|---|---|---|---|
| Sign in to the portal | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Register a passkey | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| See the subject list | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| Create a subject | ✅ | — | ✅ | — | — | — |
| Archive a subject | ✅ | — | — | — | — | — |
| See the uploads list | ✅ | ✅ | ✅ | ✅ | — | ✅ |
| Submit imaging | ✅ | — | ✅ | — | — | — |
| Retrigger a failed upload | ✅ | — | — | — | — | — |
| Open a study in the viewer | ✅ | ✅ | ✅ | ✅ | — | ✅ |
| Complete and e-sign a report | ✅ | ✅ | — | — | — | — |
| Modify a report you signed | ✅ | ✅ | — | — | — | — |
| Raise or answer a query | ✅ | ✅ | ✅ | ✅ | — | ✅ |
| Delete or restore a series | ✅ | — | — | — | — | — |
| Download an export | ✅ | ✅ | — | — | — | — |
| Schedule a report by email | ✅ | — | — | — | — | — |
| Author and export the DTA | ✅ | — | — | — | — | — |
| See who has access | ✅ | — | — | ✅ | — | ✅ |
| Invite a user | ✅ | — | — | Own sites | — | ✅ |
| Change a role or remove access | ✅ | — | — | Own sites | — | ✅ |
| Read the audit log | ✅ | — | — | — | — | — |
| Configure timepoints, sites, and forms | ✅ | — | — | — | — | — |
| View billing and invoices | ✅ | — | — | — | ✅ | ✅ |
Own sites — a CRA acts only within the sites they are assigned to, and only on uploaders. See the CRA limits.
Notes on specific actions
- Reports you did not sign. Readers and Admins can complete and e-sign reports, but a reader cannot modify someone else's signed report — the drawer opens read-only. Every edit to a signed report requires a new e-signature and is recorded in the audit log.
- E-signing requires a passkey. The action is unavailable until you have registered one. See Signing in with a Passkey.
- Exports follow report access. Anyone who can read reports can download them, which is why Readers as well as Admins can use the Export Data panel. Scheduling an export to send automatically is an Admin action.
Verifying your access
If an expected button or screen is missing:
- Confirm you selected the correct study in the portal — your role can differ per study.
- Ask an admin to verify your role on that study from Settings → Users.
- Sign out and sign back in after any role change.
For session and sign-in issues, see Getting Access.