Exposure List Visibility
Who is this for? Compliance administrators and tenant user managers who need different groups of users to see different exposure information.
Exposure list visibility controls which exposure lists — and therefore which exposures — each user in your organization can see. You assign users to visibility roles, and grant each role access to a set of exposure lists. Once enforcement is on, a user sees exposures only from the lists their roles grant.
Exposure list visibility is enabled per organization. If you don't see the visibility controls described here, contact your Altana representative to discuss enabling it for your tenant. When it is not enabled, all users see the exposures from every list your organization has turned on.
When to use exposure list visibility
- When a compliance administrator needs to limit sensitive exposure categories — for example, forced-labor lists — to the teams responsible for acting on them.
- When your organization has users in jurisdictions or roles where viewing certain risk categories raises legal or policy concerns, and those users should be onboarded without access to that information.
- When different departments — sourcing, legal, sustainability, customs — each need a view scoped to the risk information relevant to their work.
Visibility roles
Altana provides a set of preset visibility roles. The labels describe typical enterprise teams, but they carry no built-in behavior — each role sees exactly the lists you grant it, so your organization decides what each role means:
- Compliance User
- Customs & Trade User
- Legal User
- Procurement User
- Sourcing User
- Sustainability User
Before you start
- The exposure lists you plan to grant must be enabled for your organization on the Exposure Lists tab. A list that is disabled for the organization is hidden from everyone, regardless of role access.
- Decide how your users map onto the visibility roles, and which lists each role should see, before enforcement is turned on for your organization. Work with your Altana representative on this mapping — visibility roles are assigned to users as part of user setup.
Configure role access before enforcement is enabled. Once enforcement is on, users see only the lists their roles grant — if enforcement is turned on before any role-to-list access is configured, users holding visibility roles stop seeing exposure lists entirely.
How it works
- Segment your users into visibility roles — for example, your compliance department becomes Compliance Users and your sourcing offices become Sourcing Users.
- Open Settings from the user menu and select the Exposure Lists tab.
- Open the Exposure List Visibility dialog.
- Choose the roles you want to configure, then select the exposure lists those roles should be able to see, and save.
- Ensure each user is assigned the right visibility roles. Role assignment happens during user setup — coordinate with your Altana representative when adding users who need specific visibility.
What users see
With enforcement on, each user sees exposures only from the lists their roles grant — in search results, company profiles, and other surfaces where exposures appear. Users are not shown the visibility configuration itself; they simply see the exposure information relevant to them.
Constraints and caveats
- Roles are additive. Roles grant access; they never revoke it. A user with multiple roles sees the combined set of lists those roles grant.
- Organization settings win. Role access applies only to lists that are enabled for your organization. Disabling a list on the Exposure Lists tab hides it from everyone.
- An unconfigured role sees nothing. If enforcement is on and a user's roles grant no lists, that user sees no exposure information. Revisit the role-to-list mapping if users report missing exposures.
- Labels are conventions. The role names describe common team shapes; they don't change what a role can see. Grant each role the lists that match how your organization actually divides the work.
Related
- Exposure Lists — choose which lists are active for your organization.
- Role Groups — manage what users can do across the tenant.
- Exposure Lists (Concepts) — the concepts behind exposure lists and how they're applied.