IPRally combines a small set of roles with individually assignable feature permissions and contextual factors like your company and license tier. Access isn't just a fixed bundle unlocked by a role. Every action is checked against who you are, what role you hold, which specific permissions you've been given, and where you belong. This gives at least as much precision as a standard fixed-role system, because rights can be granted one at a time instead of only in preset bundles.
Role | Who holds it | What it can do |
Regular User | Any team member added to your account | Searches, reviews patents, and works within the search cases, collections, and projects they've been given access to. Can also be granted specific feature permissions (e.g., commenting, tagging, AI search tools) one at a time, within what your license tier allows. |
Company Admin | One or more people your organization designates | Invites, activates, deactivates, and manages other users in your company. Assigns the Regular User or Company Admin role and individual feature permissions. Manages user groups. Administrative rights are limited to your own company. |
SSO Admin | A technical contact for organizations using single sign-on | Has the same day-to-day administrative rights as a Company Admin. Unlike Company Admin, this role can only be granted by IPRally, not by your own admins. It's reserved for the person managing your SSO configuration. |
IPRally internal support access | A small number of IPRally staff | Elevated access used only to operate the platform and support customers, such as account setup and troubleshooting, subject to internal access review, multi-factor authentication, and logging. |
Least privilege and separation of duties
Roles and permissions are assigned separately. A role decides administrative rights. Feature permissions, like commenting or tagging, are granted individually on top, so a user only holds what they actually need.
No self-escalation. No account can deactivate, delete, or change the role of itself, preventing a single account from expanding its own access.
Everything is scoped to your company. Your admins can only see and manage users, roles, and permissions inside your own organization. They never have access to another customer's.
Elevated internal access is restricted. The roles used by IPRally staff are separate from customer roles, and your own admins cannot create, grant, or modify them.
Have questions about how a specific permission or role applies to your organization? Reach out to your IPRally account manager or our support team at support@iprally.com.
