Within Continuum GRC, the Administrator is the platform-management role. Where an Examiner is primarily responsible for performing assessment work, the Administrator is responsible for configuring, governing, and supporting the environment in which that work happens.

Based on the internal Continuum GRC material, administrative capabilities include managing users and their access, maintaining platform configuration, supporting entities and assessments, and resolving assignment or integration issues. For example, the Examiner guidance notes that administrative roles are explicitly surfaced in the platform, and that user management includes creating users, suspending/unblocking them, and removing access.

In practical terms, I would characterize the Administrator role as responsible for:

  • User and access administration: creating accounts, assigning appropriate roles/entities, and managing account status.
  • Platform and assessment configuration: setting up or maintaining the structures that users and examiners work within.
  • Permission and visibility management: ensuring people can see the appropriate clients, projects, forms, and functions.
  • Operational support: addressing configuration, mapping, access, and integration issues that prevent the assessment team from working correctly.
  • Higher-privilege platform functions: performing administrative activities that are intentionally outside the normal Examiner workflow.

The key distinction is therefore: Administrator manages Continuum GRC; Examiner uses Continuum GRC to conduct and manage assessments.

There is some overlap because the Examiner role itself has elevated capabilities—for example, the internal Examiner guide says Examiners can view/add users and suspend, unblock, or delete a user. So “Administrator” should not simply be interpreted as “the only role that can manage users.” The more meaningful distinction is system/environment ownership versus assessment execution.

If you’re defining the roles for documentation or a permissions matrix, a concise definition would be: Administrator — manages the Continuum GRC environment, including users, access, configuration, entities, assessment setup, and platform-level operational controls.

Within Continuum GRC, the Examiner is the assessment-side role responsible for reviewing and validating a client’s compliance work. The Examiner uses the platform to manage assigned assessments, evaluate controls and evidence, communicate deficiencies, and drive controls toward completion. The internal Examiner Guide describes the workflow as reviewing, updating, and managing “controls, evidence, and action items.”

In practical terms, an Examiner:

  • Reviews controls and supporting evidence to determine whether requirements are adequately satisfied. The platform provides Risk Score and AI-assisted tools to help evaluate test descriptions, uploaded artifacts, testing, and control responses.
  • Manages assessment status. Examiners can move work through statuses such as Under Review, Needs Attention, Complete, or Failed. “Complete” represents work reviewed and approved by the assessor, while “Failed” indicates that requirements were not met.
  • Creates and manages Action ITAMs when the client needs to provide clarification, remediation, missing evidence, or other follow-up. The guide explicitly notes that Action ITAMs drive the Examiner’s workload.
  • Works assigned control groups. Controls can be assigned between examiners, marked complete when the required work is finished, and synchronized with the Teamwork integration.
  • Tracks assessment health and workload. The Examiner sees assigned projects, completion/risk indicators, timeline health, time spent versus estimates, and assigned Action ITAMs from the Priorities page.
  • Uses assessment-management tools including flagged-control review, bulk Action ITAM assignment, status rollups, orphan-data detection, evidence mapping, AI-assisted control guidance, reports, and dashboards.
  • Supports client access and collaboration. Examiner permissions also include viewing/adding Continuum GRC users and managing user access. During active collaboration, the guide recommends keeping the assessment out of Read Only Mode so clients can upload evidence and make required updates.

So the simplest description is: the Examiner is the operational assessor inside Continuum GRC—the person who takes the client's submitted control information and evidence, tests/reviews it, identifies gaps, requests corrections or additional evidence, records assessment results, and moves the assessment toward an auditable final state. The platform is essentially organized to give that Examiner a centralized workspace for their assigned projects and assessment workload.

Within Continuum GRC, the Facilitator – Readiness Provider is the advisory/pre-assessment role. Its purpose is to help an organization become ready for the formal assessment, rather than to act as the independent Examiner who ultimately evaluates the organization.

In practical terms, the Facilitator/Readiness Provider would typically:

  • Guides the client through readiness activities and helps them understand what a framework or assessment requires.
  • Reviews controls and evidence for readiness, identifying gaps before those items reach the formal Examiner.
  • Helps develop and improve documentation and evidence, including control narratives, policies, procedures, and supporting artifacts.
  • Coordinates remediation, helping the client resolve deficiencies and organize outstanding work.
  • Facilitates the assessment process, serving as an intermediary between the organization’s contributors and the eventual assessment/testing process.
  • Does not serve as the final independent assessor. That separation is important: readiness work prepares and advises; examination determines whether requirements have actually been satisfied.

The internal materials show Continuum GRC being used for dedicated FedRAMP facilitation and remediation work, alongside formal readiness-assessment deliverables such as FedRAMP Readiness Assessment Reports.

Within Continuum GRC, a User is generally the client/contributor role—the person responsible for supplying and maintaining the information that an Examiner evaluates.

A User typically:

  • Works on assigned controls or requirements, providing the organization’s responses and implementation information.
  • Uploads and manages evidence supporting those responses.
  • Responds to Action ITAMs when an Examiner requests clarification, additional evidence, corrections, or remediation.
  • Updates assessment information while the assessment is open for collaboration.
  • Tracks progress on the controls, tasks, and other items available to them.
  • Operates within assigned permissions, rather than administering the overall Continuum GRC environment or making the Examiner’s assessment determination.

The Examiner workflow reinforces this relationship: Examiners review controls and evidence and use Action ITAMs to drive follow-up work, while clients need appropriate access to make updates and upload evidence during an active assessment