Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

Lieferanten/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
Isan (Diskussion | Beiträge)
Keine Bearbeitungszusammenfassung
KoKl (Diskussion | Beiträge)
Keine Bearbeitungszusammenfassung
 
(27 dazwischenliegende Versionen von 3 Benutzern werden nicht angezeigt)
Zeile 1: Zeile 1:
Under "Administration → Suppliers" you find all suppliers, regardless of the selected management system.
Under “Administration → Suppliers,” you will find a list of all suppliers. Since suppliers are master data, this view is independent of the selected management system. For this menu item to be available, the system must have a Supplier Risk Management license, and your user must have the “Expert” role in SRM. Experts with an SRM license will find an overview of suppliers on this page. The page displays their protection requirement class, code, name, country, status (Active or Deactivated), and, optionally, the expiration date.


For the menu item to be available, one needs to have a Supplier Risk Management license and be assigned the role Expert in SRM.
[[Datei:SM_Lieferanten_Übersicht.png||left|thumb|900px|Overview of the suppliers]]<br clear=all>


SRM Experts find an overview of all suppliers on this page with their code, name, country, state (active or deactivated) and optionally their expiration date.
The displayed protection needs class can be limited to the current management system or shown across all management systems. Per se, the protection needs corresponds to the classification configured in Risk management > Settings. If you select the display of all management systems, that means those that use the same protection needs classification. Therefore, the protection need can look different depending on which management system you are currently in.
 
[[Datei:SM_Lieferanten_Übersicht.png||left|thumb|900px|Overview of the suppliers]]<br clear=all>


===Create/edit suppliers===
===Create/edit suppliers===
Suppliers can be created and their basic data recorded here. Other than the code and name, this also includes details on their address and general contact.<p>Special fields:
Suppliers can be created and their basic data recorded here. Other than the code and name, this also includes details on their address and general contact.<p>Special fields:
[[Datei:LieferantErstellen.png||center|thumb|800px|Create/edit supplier]]<br clear=all>
{| class="wikitable"
{| class="wikitable"
!Expiration date
!External ID
|A date can be entered from here, after which the supplier is no longer able to respond to or view assessments. A month before the expiration date, any supplier users are informed of this. The date can be modified at any time. Expired suppliers are shown as such in overviews. If you set an expiration date that lies <i>before</i> the answer deadline of a sent assessment, you receive a warning.<br><br>The expiration date can also be set automatically. For this, define a period under Administration > Global Settings > Security settings for supplier risk managmeent, then the expiration date will be preset by HITGuard accordingly.<br><br><u>Note:</u>Expired suppliers do not use up a license.<br><u>Caution:</u> The deactivated slide control is <i>not</i> automatically adjusted.
|This is the ID of the supplier Lieferanten, which identifies the supplier in an excel  [[Special:MyLanguage/Datenimport|import]] or an import via [[Special:MyLanguage/Datenimport/-export_Schnittstelle| REST API]].  
|-
!Deactivated
|This switch is visible as soon as the supplier is created (after the first save). A deactivated supplier is no longer able to respond to or view assessments. Any of the supplier's users are informed of this. Deactivated suppliers are marked as such in overviews and reviews.<br><br<u>Note:</u> Deactivated suppliers do not use up a license.
|-
|-
!External ID
!Internal contact
|This is the ID of the supplier in other systems. It is especially relevant when im- and exporting via the REST API.
|Here you can enter a HITGuard user (or a team) who will serve as the point of contact for the supplier — fore example one of your <i>Procurement Managers</i>. HITGuard will then automatically contact this user as the expiration date approaches. If you have not entered anyone here, HITGuard will send the email to the “internal team” that you have specified in the [[Special:MyLanguage/Globale_Einstellungen#Sicherheitseinstellungen_für_Lieferanten-Risikomanagement|global settings]].  
|-
|-
!Score
!Score
Zeile 23: Zeile 21:
|-
|-
!Protection needs
!Protection needs
|Here you can record the supplier's protection needs, which is especially important for the structural analysis.
|Here you can manually enter the supplier's protection needs class. This setting overrides the protection needs class determined in the [[Special:MyLanguage/Strukturanalyse|Structure Analysis]] based on the [[Special:MyLanguage/Schutzbedarf|protection needs analysis]] and contextual relationships.
|-
|-
!Supplier categories
!Supplier categories
|You can assign suppliers to different categories in order to better order and sort them.
|You can assign suppliers to different categories in order to better order and sort them.  You can create these categories at <i> Administration > Suppliers > Supplier Categories </i>.
|-
|-
!External metric
!External metric
|You can record an evaluation metric from another system in this text field. This can also be done via the importer.
|You can record an evaluation score from another system in this text field. This can also be done via the importer.
|-
|-
!Justification
!Justification
|Here you can justify the scores and assessments you gave the supplier.
|Here you can justify the scores and assessments.
|-|}
|-
!Expiration date
|Here you can enter the date on which the supplier will be deactivated automatically. After that date, the supplier’s users will no longer be able to log in to the supplier portal, view surveys, or respond to them. The supplier will also no longer <b>use a license</b>. You can change or delete the date at any time. If you set an expiration date that <i>precedes</i> the response deadline for a supplier questionnaire that was already sent to the supplier, you will receive a warning. When you create the supplier for the first time, HITGuard automatically enters the expiration date. To do this, HITGuard adds the time period you defined in the [[Special:MyLanguage/Globale_Einstellungen#Sicherheitseinstellungen_für_Lieferanten-Risikomanagement|global settings]] to today’s date.


[[Datei:LieferantErstellen.png||left|thumb|900px|Create/edit supplier]]<br clear=all>
|-
!Deactivated
|This switch becomes visible only after you save for the first time. If the toggle is set to “No", the supplier is active and uses a license. Supplier users can log in. If it is set to “Yes,” the supplier is deactivated, does not use any licenses, and is excluded from the system.
You can deactivate and reactivate a supplier at any time by toggling the switch. When you deactivate it manually, the expiration date is set to today’s date. When you activate it, the date is cleared. Supplier users are notified of these cahnges.
|-
|}


===Create/edit supplier users===
===Supplier Access: Create & Edit Supplier Users===
Supplier users for the individual suppliers can be created/edited here.<p>For every user, record first name, last name and e-mail address. The e-mail address is a mandatory field, as it also serves as the username for the user's login. Users that have already logged in once using the welcome link (sent automatically when creating the user) and created their password are marked as "verified" in the overview. Users who have entered their password incorrectly too many times and locked themselves out, are marked as "locked out" in the overview. This can be remedied by resending the welcome e-mail.<p><u>Important:</u> Supplier users can only be created if a company name has been entered in "Administration → Global Settings".<p>Special fields:
Here you can create and manage supplier users for each supplier. For each user, you must enter the first name, last name, and email address. The email address is a required field because it also serves as the user’s login username. Users who have already registered via the welcome link (which is sent automatically when the user is created) and set their password are marked as “verified” in the overview. Users who have entered their password incorrectly too many times and locked themselves out are marked as “locked” in the overview. This can be resolved by resending the welcome email. <p><u>Important</u>: Supplier users can only be created if a company name is entered under “Administration → Global Settings.
 
[[Datei:LieferantBenutzer.png||left|thumb|900px|creating/editing Supplier users]]<br clear=all>
 
Some fields have special functions:
{| class="wikitable"
{| class="wikitable"
!Administrator
!Administrator
|A supplier user can be made into a supplier administrator with a checkmark here (<u>not</u> for the entire application). This user (multiples possible) then has the possibility to create and edit users themselves in their own supplier portal. The checkmark can be removed as well.
|Here, a supplier user can be designated as an administrator on the supplier’s side by checking the box (<u>not</u> for the entire application). This user (or users) can then create and edit other users for their organization. The checkmark can also be removed.
|-
|-
!Deactivated
!Deactivated
|A deactivated supplier user is no longer able to respond to or view assessments. A supplier user can be deactivated or reactivated at any time. They are informed of this via e-mail.<br><br>When deactivating a user there is the option to pseudonymize them. This cannot be undone. If the user was an administrator, those rights are withdrawn upon pseudonymization.
|A deactivated supplier user is no longer authorized to respond to or view audits. A supplier user can be deactivated or reactivated at any time. They will be notified of this via email. <br><br>When deactivating a user, you also have the option to pseudonymize them. This cannot be undone. If the user was an administrator, these rights are also revoked when the user pseudonymized.
|-
|-
!Button: Resend welcome mail
!Paperplane-Button: Resend Welcome Email
|Upon creation every supplier user receives a welcome mail, through which they can log in for the first time and create their password. From this moment on, their login works. The link for the initial login is valid for 48 hours and can be resent if the user has not logged in within that timeframe. Resending the welcome mail also resets the password and any 2-factor-authentication.
|Every supplier user receives a welcome email when first created. They can use it to log in for the first time and create their own password. The link for the initial login is valid for 48 hours and can be resent if the user has not logged in during that time. Resending the welcome email also resets the password and any two-factor authentication.
|-
|-
!Button: Delete user
!Trashcan-Button: Delete user
|A supplier user can be deleted with this button. They can then no longer log in and are not able to respond to or view assessments. They are informed of this via e-mail.<br><br><u>Note:</u> Verified supplier users cannot be deleted but only deactivated.
|This button allows you to delete a supplier user. They will then no longer be able to log in and will no longer be authorized to respond to or view reviews. They will be notified of this via email.<br><br><u>Note:</u> Verified supplier users cannot be deleted, only deactivated.
|-
|-
|}
|}
[[Datei:LieferantBenutzer.png||left|thumb|900px|Create/edit supplier user]]<br clear=all>
 


When deactivating or deleting a user the system warns you if
When deactivating or deleting a user the system warns you if
Zeile 61: Zeile 70:
The deactivation including pseudonymization can be undone so long as one has not clicked Save. When deleting, the system asks back whether one is sure one wants to delete the user.
The deactivation including pseudonymization can be undone so long as one has not clicked Save. When deleting, the system asks back whether one is sure one wants to delete the user.


===Suppliers as interview partners===
===Suppliers as Interview Partners===
If the option "Supplier evaluation" is activated under Risk management → Settings, then the checkbox "Supplier assessent" is available when creating a gap analysis or review result. Then the created suppliers are available as interview partners instead of regular HITGuard users. Suppliers are also saved as linked entities in all review objects. If the review is created as a self assessment, the supplier's users can see it in their portal. This is not the case with interviews.
If the “Supplier evaluation” option under Risk Management → Settings is enabled, the “Supplier Review” checkbox will be available when creating gap analyses and review results. In this case, the created suppliers will be available as interview partners instead of regular HITGuard users. Suppliers are also stored as linked entities in all audit objects. If the review is created as a <i>self-assessment</i>, any users of the supplier will see it in their portal. This is not the case for <i>interviews</i>.
[[Datei:Checkbox_Lieferantenüberprüfung.png|left|thumb|500px|Checkbox for supplier assessments]]<br clear=all>
 
The users of a selected supplier have the option in their portal to view the self assessment, respond to it, and return it. This works the same as the response by an interview partner or responsible im a regular self assessment. Interviews are available for the use case of a supplier risk manager wanting to enter the review information into the system themselves, without any assessment being sent to the supplier at all.<p>If a supplier has no users, HITGuard warns about this circumstance.
:::[[Datei:Checkbox_Lieferantenüberprüfung.png|left|thumb|500px|Checkbox for supplier evaluations]]<br clear=all>
 
Users of the registered supplier can then view, complete, and submit the self-assessment in the supplier portal. This works exactly the same way as when a respondent or responsible party completes a [[Special:MyLanguage/Überprüfung|regular self-assessment]]. Interviews are intended for cases where you enter the review data yourself and do not send any review to the supplier’s users at all.
 
If a supplier has no users, the supplier cannot receive a self-assessment. In this case HITGuard will notify the user of this fact.
 
====Notifications====
====Notifications====
* The users of the selected supplier receive an e-mail with an invitation to respond to the review.
* Users of the registered supplier receive an email inviting them to complete the review.
* The users of the selected supplier receive an e-mail with a warning if the response deadline is up.
* Users of the registered supplier receive an email alert when the response deadline is approaching.
* The users of the selected supplier (or just the administrator) receive an e-mail with a warning when the expiration date of their accounts is nigh.
* Users of the registered supplier (or only the administrator) will receive an email with a warning when their account’s expiration date approaches.
* The optionally entered internal team responsible for handling the supplier receives an e-mial with a warning when the expiration dates of the accounts is nigh.
* The optional internal team responsible for the supplier will receive an email with a warning when the accounts’ expiration dates approach.


===Supplier portal===
===Supplier Portal===
Using your regular link for HITGuard, configured for your organization, with the addition of "/Supplier", supplier users can log into HITGuard.<p>Suppliers who have forgotten their password can also reset it here. Any 2-factor-authentication is also reset along with it.
Supplier users can log in to HITGuard via a dedicated portal. By default, you can find it at the regular URL used by your HITGuard system, with the suffix “/Supplier” (e.g., togetherexample.hitguard.at/Supplier) attached. Suppliers who have forgotten their password can also reset it here. This will also reset the two-factor authentication.
[[Datei:SM_LIeferantenportal.png||left|thumb|900px|Supplier login]]<br clear=all>
[[Datei:SM_LIeferantenportal.png||left|thumb|700px|Login for suppliers]]<br clear=all>
In this portal supplier users see the reviews assigned to them and can also manage their 2-factor-authentication. Find more on 2-factor-authentication [[Special:MyLanguage/2FA|here]]. Administrators additionally see the tab "User management", in which they can create further users and edit existing ones.<p>Badges beside the folders show how many reviews in which state are waiting for interaction. These are also highlighted in bold. Overdue reviews, meaning whose response deadline has passed, are also especially highlighted with a badge.<p>Supplier users can view assessments here, respond to them, and retourn them to the risk manager.
In this portal, supplier users can view the checks assigned to them and also have the option to manage their two-factor authentication. You can find more information about two-factor authentication [[Special:MyLanguage/2FA|here]]. Administrators also see the “User Management” tab, where they can create additional users and edit existing ones.<p>Badges on the folders show how many checks are in processing and their respective statuses. These are also highlighted in bold in the overview. Overdue reviews - the reviews whose response deadline has passed - are also specially highlighted with a badge.<p>Supplier users can view the reviews here, respond to them, and return them to the risk manager.
[[Datei:SM_Supplierportal_Überprüfungen_TM.png||left|thumb|900px|Supplier portal]]<br clear=all>
[[Datei:SM_Supplierportal_Überprüfungen_TM.png|left|thumb|900px|Supplier Portal]]<br clear=all>


===Supplier categories===
===Supplier Categories===
Here you can create and manage categories for your suppliers. Alternatively, you can also create supplier categories by typing them directly into the respective field on the supplier page and confirm the creation. All categories are then shown in this list.
Here you can create and manage categories for your suppliers. Alternatively, you can create supplier categories by entering them directly into the corresponding field for the supplier and confirming the creation. All categories will then appear in this list.
[[Datei:Lieferantenkategorien.png||left|thumb|900px|Supplier categories]]<br clear=all>
[[Datei:Lieferantenkategorien.png|left|thumb|900px|Supplier Categories]]<br clear=all>


===Online help for supplier users===
===Online help for supplier users===
A help page you can share with the supplier users can be found [[Special:MyLanguage/Lieferantenportal|here]].<br>
You can find a help page you can share with the supplier users [[Special:MyLanguage/Lieferantenportal|here]].<br>
A link to the help page for supplier users is also found in their welcome e-mail.
A link to the help page for supplier users is also found in their welcome e-mail.

Aktuelle Version vom 1. April 2026, 12:04 Uhr

Under “Administration → Suppliers,” you will find a list of all suppliers. Since suppliers are master data, this view is independent of the selected management system. For this menu item to be available, the system must have a Supplier Risk Management license, and your user must have the “Expert” role in SRM. Experts with an SRM license will find an overview of suppliers on this page. The page displays their protection requirement class, code, name, country, status (Active or Deactivated), and, optionally, the expiration date.

Overview of the suppliers


The displayed protection needs class can be limited to the current management system or shown across all management systems. Per se, the protection needs corresponds to the classification configured in Risk management > Settings. If you select the display of all management systems, that means those that use the same protection needs classification. Therefore, the protection need can look different depending on which management system you are currently in.

Create/edit suppliers

Suppliers can be created and their basic data recorded here. Other than the code and name, this also includes details on their address and general contact.

Special fields:

Create/edit supplier


External ID This is the ID of the supplier Lieferanten, which identifies the supplier in an excel import or an import via REST API.
Internal contact Here you can enter a HITGuard user (or a team) who will serve as the point of contact for the supplier — fore example one of your Procurement Managers. HITGuard will then automatically contact this user as the expiration date approaches. If you have not entered anyone here, HITGuard will send the email to the “internal team” that you have specified in the global settings.
Score Here you can give the supplier a score per the CMMI degree of maturity model.
Protection needs Here you can manually enter the supplier's protection needs class. This setting overrides the protection needs class determined in the Structure Analysis based on the protection needs analysis and contextual relationships.
Supplier categories You can assign suppliers to different categories in order to better order and sort them. You can create these categories at Administration > Suppliers > Supplier Categories .
External metric You can record an evaluation score from another system in this text field. This can also be done via the importer.
Justification Here you can justify the scores and assessments.
Expiration date Here you can enter the date on which the supplier will be deactivated automatically. After that date, the supplier’s users will no longer be able to log in to the supplier portal, view surveys, or respond to them. The supplier will also no longer use a license. You can change or delete the date at any time. If you set an expiration date that precedes the response deadline for a supplier questionnaire that was already sent to the supplier, you will receive a warning. When you create the supplier for the first time, HITGuard automatically enters the expiration date. To do this, HITGuard adds the time period you defined in the global settings to today’s date.
Deactivated This switch becomes visible only after you save for the first time. If the toggle is set to “No", the supplier is active and uses a license. Supplier users can log in. If it is set to “Yes,” the supplier is deactivated, does not use any licenses, and is excluded from the system.

You can deactivate and reactivate a supplier at any time by toggling the switch. When you deactivate it manually, the expiration date is set to today’s date. When you activate it, the date is cleared. Supplier users are notified of these cahnges.

Supplier Access: Create & Edit Supplier Users

Here you can create and manage supplier users for each supplier. For each user, you must enter the first name, last name, and email address. The email address is a required field because it also serves as the user’s login username. Users who have already registered via the welcome link (which is sent automatically when the user is created) and set their password are marked as “verified” in the overview. Users who have entered their password incorrectly too many times and locked themselves out are marked as “locked” in the overview. This can be resolved by resending the welcome email.

Important: Supplier users can only be created if a company name is entered under “Administration → Global Settings.”

creating/editing Supplier users


Some fields have special functions:

Administrator Here, a supplier user can be designated as an administrator on the supplier’s side by checking the box (not for the entire application). This user (or users) can then create and edit other users for their organization. The checkmark can also be removed.
Deactivated A deactivated supplier user is no longer authorized to respond to or view audits. A supplier user can be deactivated or reactivated at any time. They will be notified of this via email.

When deactivating a user, you also have the option to pseudonymize them. This cannot be undone. If the user was an administrator, these rights are also revoked when the user pseudonymized.
Paperplane-Button: Resend Welcome Email Every supplier user receives a welcome email when first created. They can use it to log in for the first time and create their own password. The link for the initial login is valid for 48 hours and can be resent if the user has not logged in during that time. Resending the welcome email also resets the password and any two-factor authentication.
Trashcan-Button: Delete user This button allows you to delete a supplier user. They will then no longer be able to log in and will no longer be authorized to respond to or view reviews. They will be notified of this via email.

Note: Verified supplier users cannot be deleted, only deactivated.


When deactivating or deleting a user the system warns you if

  • the user is assigned to a not-deleted assessment, and/or
  • the user is the last administrator user of the supplier.

The deactivation including pseudonymization can be undone so long as one has not clicked Save. When deleting, the system asks back whether one is sure one wants to delete the user.

Suppliers as Interview Partners

If the “Supplier evaluation” option under Risk Management → Settings is enabled, the “Supplier Review” checkbox will be available when creating gap analyses and review results. In this case, the created suppliers will be available as interview partners instead of regular HITGuard users. Suppliers are also stored as linked entities in all audit objects. If the review is created as a self-assessment, any users of the supplier will see it in their portal. This is not the case for interviews.

Checkbox for supplier evaluations

Users of the registered supplier can then view, complete, and submit the self-assessment in the supplier portal. This works exactly the same way as when a respondent or responsible party completes a regular self-assessment. Interviews are intended for cases where you enter the review data yourself and do not send any review to the supplier’s users at all.

If a supplier has no users, the supplier cannot receive a self-assessment. In this case HITGuard will notify the user of this fact.

Notifications

  • Users of the registered supplier receive an email inviting them to complete the review.
  • Users of the registered supplier receive an email alert when the response deadline is approaching.
  • Users of the registered supplier (or only the administrator) will receive an email with a warning when their account’s expiration date approaches.
  • The optional internal team responsible for the supplier will receive an email with a warning when the accounts’ expiration dates approach.

Supplier Portal

Supplier users can log in to HITGuard via a dedicated portal. By default, you can find it at the regular URL used by your HITGuard system, with the suffix “/Supplier” (e.g., togetherexample.hitguard.at/Supplier) attached. Suppliers who have forgotten their password can also reset it here. This will also reset the two-factor authentication.

Login for suppliers


In this portal, supplier users can view the checks assigned to them and also have the option to manage their two-factor authentication. You can find more information about two-factor authentication here. Administrators also see the “User Management” tab, where they can create additional users and edit existing ones.

Badges on the folders show how many checks are in processing and their respective statuses. These are also highlighted in bold in the overview. Overdue reviews - the reviews whose response deadline has passed - are also specially highlighted with a badge.

Supplier users can view the reviews here, respond to them, and return them to the risk manager.

Supplier Portal


Supplier Categories

Here you can create and manage categories for your suppliers. Alternatively, you can create supplier categories by entering them directly into the corresponding field for the supplier and confirming the creation. All categories will then appear in this list.

Supplier Categories


Online help for supplier users

You can find a help page you can share with the supplier users here.
A link to the help page for supplier users is also found in their welcome e-mail.