Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

Benutzer und Benutzerrollen/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
KoKl (Diskussion | Beiträge)
Keine Bearbeitungszusammenfassung
KoKl (Diskussion | Beiträge)
Keine Bearbeitungszusammenfassung
 
(3 dazwischenliegende Versionen desselben Benutzers werden nicht angezeigt)
Zeile 22: Zeile 22:
=== Professional ===
=== Professional ===


<div class="mw-translate-fuzzy">
 
Users of this role support the experts of the management systems in the fulfillment of their tasks. A professional has access to all tasks in the management systems they are assigned to, but has limited editing rights.
[[Datei:02Prof.png|right|thumb|400px|Menu of a Professional user with the risk management module and case management add-on open]] Professionals can view, edit, and create data in the [[Special:MyLanguage/Managementsysteme|management system]]. In addition, a Professional can do everything a Practitioner can do (see above). Professionals are designed as support for the management system or for Experts. <p>
* Risk management:
To view and edit data, Professionals must be added to the management system. They can then create [[Special:MyLanguage/Schwachstellen|analyses]] and risks, assign [[Special:MyLanguage/Aktuelle_Maßnahmen|measures]] and [[Special:MyLanguage/Kontrolldefinitionen|controls]], generate reports, and evaluate KPIs in the [[Special:MyLanguage/Risikomanagement_Dashboard|dashboard]]. <p>
** A Professional can create and manage analyses and risks.
They can also work in the respective add-on modules. This includes, among other things:
* Audit management
{|class="wikitable" style="float:right"
** A Professional can create, manage and perform audits/audit programs.
!Module !! Capabilites of a Professional
* Measures and controls.
|-
** They can create and manage measures and controls.
| Audit management ||
* Data Protection
manage [[Special:MyLanguage/Auditplanung|Audits]] and Audit programs.
** A Professional can create processing activities, assign TOMs, and manage externals.
|-
* Case Management
|data protection|| create [[Special:MyLanguage/Verarbeitungsregister|processing activities]] and assign TOMs.
** A Professional can process reports and assign periods.
|-
* Doc-management
| case management||work with [[Special:MyLanguage/Meldungen|tickets]] and add deadlines.
** A Professional can create and edit directories.
|-
** A Professional can upload and edit files.
| Docu management || [[Special:MyLanguage/Dokumentenmanagement|uploading documents hochladen]] and editing registries.
* ESG management
|-
** A Professional can create and manage impacts and ESG topics.
| ESG management || create and edit [[Special:MyLanguage/Auswirkungen|Impacts]].
*Supplier risk management
|-
**A Professional can assign a review to a supplier as the interview partner.
| Supplier Risk Management||[[Special:MyLanguage/Supplier_Risk_Management|Sending]] questionnaires to suppliers.
</div>
|}<br clear=all>


=== Expert ===
=== Expert ===


<div class="mw-translate-fuzzy">
 
This role may participate in one or more [[$A_manSys|management systems]] in your organization.  
[[Datei:02Exp.png|right|thumb|400px|Menu of an Expert user with open risk policy. Note the second-to-last module “Administration”.]] Expert users are the most powerful role in the system and are therefore intended for managerial functions within the management system. They can do everything that Professionals and Practitioners can do (see above). In addition, Experts can use certain special functions, such as the [[Special:MyLanguage/Fortschrittsmeldungen#Eingreifen_in_Fortschrittsmeldungen|authorized editing mode]]. Experts also manage basic settings, management systems, evaluation tools, and master data. For this purpose, Experts have access to the “Administration” module: <p>
* Risk management:
<b>basic settings</b><br>Expert users can configure basic settings that apply to the entire HITGuard installation in the [[Special:MyLanguage/Globale_Einstellungen|global settings]] and the [[Special:MyLanguage/Risikopolitik|risk policy]]. Experts also have access to the settings of the respective modules (the screenshot shows the risk management settings as the last item in the open module). <p>
** An Expert can perform analyses and create risks.
<b>management systems</b><br> Just like Professionals, Experts must be added to the [[Special:MyLanguage/Managementsysteme|management system]] to view its data. However, Experts can also create and manage [[Special:MyLanguage/Managementsysteme|management systems]]. This means that Experts decide, for example, which other users (Experts, Professionals, and Observers) they add to their management system and which they do not. <p>
** Experts are responsible for the administration of the risk policy and the risk management settings.
<b>evaluation tool</b><br>In addition, an Expert can use the structural analysis. This is a central modeling tool used to relate and evaluate master data, dependencies, and risks. Learn more about it [[Special:MyLanguage/Strukturanalyse|here]].
* Audit management
<p>
** An Expert can create, manage and perform audits/audit programs.
<b>master data</b><br>Work in HITGuard is based on master data and other fundamental data that are managed by Expert users. The following table provides an overview of this data:
** Experts are responsible for the administration of audit management settings.
{|class="wikitable" style="float:right; margin-left:10px; width:900px;"
* Measures and controls
! style="text-align:left" | Type !! Menu item !! Description and core function
** An Expert can create and manage measures and controls.
|-
** Experts are responsible for the administration of the settings in the Progress Monitor.
| rowspan="7" | Master data
* Data protection
| [[Special:MyLanguage/OrgEh_-_Organisationseinheiten|organizational units]] || Represent the different departments of an organization.
** An Expert can create processing activities, assign TOMs, manage external parties and data subjects.
|-
* Case management
| [[Special:MyLanguage/Ressourcen|Resources]] || Represent the IT systems used by the organization.
** An Expert can process reports and create and manage periods.
|-
** Experts are responsible for case management settings.
| [[Special:MyLanguage/Datenkategorien|Data categories]] || Data categories represent the main types of data that are relevant for the organization.
* Docu management
|-
** An Expert can create and edit directories.
| [[Special:MyLanguage/Prozesse|Processes]] || Represent workflows that the organization performs repeatedly.
** An Expert can upload and edit files.
|-
*ESG management
| [[Special:MyLanguage/Lieferanten|Suppliers]] || Represent the companies that provide important inputs to the organization, including IT systems.
** An Expert an activate and deactivate the menu item.
|-
** An Expert can create and manage impacts and ESG topics.
| [[Special:MyLanguage/Wissensdatenbanken|Knowledge bases]] || Contain templates for questionnaires, tasks, and many other elements.
*Supplier risk management
|-
** An Expert can activate and deactivate the menu item.
| [[Special:MyLanguage/Standards_und_Normen|Standards and norms]] || Used to evaluate compliance with a standard or legal text.
** An Expert can create and manage suppliers.
|-
* Experts can create and manage management systems.
| rowspan="4" | Additional basic data in the Administration module
* Experts can access the Administration menu and thus also create assets or users.
| [[Special:MyLanguage/Teams|Teams]] || Teams can be used to group multiple users who should complete tasks together.
</div>
|-
| [[Special:MyLanguage/Textbausteine|Text blocks]] || Allow you to create text templates for specific HITGuard functions.
|-
| [[Special:MyLanguage/KI-Promptverwaltung|AI prompt management]] || Here you can manage templates for AI prompts if you use an AI integration.
|-
| [[Special:MyLanguage/Datenimport|Data import]] || Allows the import of data from Excel files. With this function, you can import risks, measures, master data, and other kinds of data.
|}


=== Admin ===
=== Admin ===


<div class="mw-translate-fuzzy">
This role only performs administrative tasks, but has no insight into data related to analyses and tasks. Many of these tasks, such as managing [[Special:MyLanguage/Managementsysteme|management systems]], [[Special:MyLanguage/Wissensdatenbanken|knowledge bases]], and users, can also be performed by Experts (see above). Other tasks can only be carried out by an administrator:
This role is responsible for administration as well as for managing other users. Administrators have no insight into data. So, although administrators can manage and create '''all''' management systems, they do not have access to their data, nor can they be defined as responsible persons.
*If an Expert user has lost their password and is locked out, the Admin can reset the password for the Expert. Passwords of other users can also be reset by an Expert. (Note: For this function, the user must log in via password, not via directory service.)
* At the first installation of the software, at least one administrator must be defined.
*The Admin can set up and activate a [[Special:MyLanguage/Datenimport/-export_Schnittstelle|REST API]] interface. <p>
* There can be several administrators.
<b>Note</b>: When initially setting up a new production system, at least one administrator must be defined. In a SaaS solution, this task can be performed by a TogetherSecure employee; for on-premises setups, the administrator must be provided by your organization.
* Performs purely administrative tasks like creating users and configuring an Active Directory.
* An admin can import knowledge bases, create a superseding version, and set it as the default version.
</div>


<span id="Observer_(Beobachter)"></span>
<span id="Observer_(Beobachter)"></span>
=== Observer ===
=== Observer ===


<div class="mw-translate-fuzzy">
Observers see the same data as Professional users (see above), but can only read it, not edit it. Just like a Professional or Expert, the Observer must be added to the [[Special:MyLanguage/Managementsysteme|management system]] they should have access to. Observer users (like Professionals and Experts) also have a functional Practitioner module and can therefore process tasks assigned to them. <p>
Users of this role have similar permissions as professionals with regard to the visibility of menu items. However, unlike professionals, they cannot make any changes to the system. They have read-only access to the software. To gain visibility into a management system, they must be added to the management system team like a professional or expert.
Observers can not only view data, but also generate reports and adjust and evaluate KPIs on dashboards. Observer roles are suitable for giving management or auditors insight into the management system.
* Risk Management:
** An Observer can view protection needs and vulnerability assessments, risks, measures, and dashboards, and generate reports.
* Audit Management.
** An Observer can view audits and audit programs.
* Measures
** An Observer can view measures, reports, assessments, and dashboards.
* Controls
** An Observer can view controls, reports, and the dashboard.
* Data protection
** An Observer can view processing activities and generate reports. TOMs and externals can be viewed without details. Data privacy impact assessments cannot be viewed.
* Case management
** An Observer can view reports and periods.
* Doc-management
** An Observer can view directories and files.
* ESG management
** An Observer can view impacts and ESG topics.
</div>


<span id="Benutzerverwaltung"></span>
<span id="Benutzerverwaltung"></span>
== User Administration ==
== User Administration ==


<div class="mw-translate-fuzzy">
[[Datei:Benutzer anlegen.PNG|thumb|right|500px|Create user]]
[[Datei:Benutzer anlegen.PNG|thumb|right|500px|600px|Create user]]
 
</div>


<div class="mw-translate-fuzzy">
=== Create user ===
=== Create user ===
There are three possibilities to create a user
There are three ways to create a user. When a user is created, they are initially only a Practitioner (see above). Additional roles can then be assigned later (see below) <p>
* Option 1: Create a user via the user list (for local logins without Active Directory).
<b>Manual entry</b> <br> Under <i> Administration → Users </i> you will find the user list. Here you can add a user by clicking the plus button. You can see the input form in the image on the right. If you choose this method, you should inform the user that the password you set is only an initial password and should be changed in their own [[Special:MyLanguage/Profil|profile]]. <p>
: Administration → Users:  In the user list, on the right margin, click on the button "Plus" to add a user. Then you can create the user with the relevant data.<br><br>
<b>Excel import</b> <br> Via the menu item [[Special:MyLanguage/Datenimport|Data import]], Experts can import user lists. This allows you to create and update users. It is also possible to create a new user by importing another element, e.g. an organizational unit. <p>
: <u> Note on the interface</u>: "Search in directory service", is only displayed if LDAP is enabled in the global settings and an Active Directory is configured. This allows users to be searched from Active Directory and created with their data in HITGuard.  
<b>Directory service connection</b> <br> If you have connected a directory service (LDAP or AD/Entra ID), you can create users directly from the directory service.
: <u>Note for Azure Active Directory (AAD)</u>: Users that were already created before LDAP activation can be linked to their Azure Active Directory account afterwards. This allows to use Single-Sign-On (SSO). This can be done by each user under their profile. (see [[$A_profile|Profile]]) Administrators can also load current data from the AAD using a button to the right of the user name. This replaces different information from HITGuard. For this, however, the user must already be linked to an AAD account.
This can be done in two ways:
* Option 2: Quick entry
*In the image on the right, you can see the field “Search in directory service” at the very top. This is only displayed if a directory service is connected. You can use it to search for a user in your directory service and import the data directly. After that, you still need to
: In the context of use, [[Special:MyLanguage/Global_Settings#ldap|Active Directory]] Integration, a new user with minimal permissions for the active module can be created via a person selection screen. To use this, type the person's name or abbreviation in a user selection box. This will load the user from the Active Directory. This user can then log in with his Active Directory data. The user roles can be expanded later, if desired.
*In many other elements in the software, you will find user selection fields, e.g. in measures. There you can select users and assign them to elements. If you have connected a directory service, HITGuard will not only suggest users in HITGuard, but also matching entries from the directory service. If you select one of these and save, the user will be imported from the directory service. (<b>Note:</b> Since other users may also have access to these elements, Professionals and, in exceptional cases, Practitioners can also create new users.)
</div>
Users created via the directory service can then simply [[Special:MyLanguage/Login_Möglichkeiten|log in]] with a click on “Sign in with Microsoft” (single sign-on) and no longer need their own HITGuard password. Even if the user was created in another way, every user can independently link their account to the directory service in their [[Special:MyLanguage/Profil|profile]] (provided a directory service is connected to HITGuard). <p>


<span id="Benutzerrollen_zuordnen"></span>
<span id="Benutzerrollen_zuordnen"></span>
<div class="mw-translate-fuzzy">
===<span id="rollen_zuordnen“></span> Assigning user roles ===
=== Assign user roles ===
 
</div>


<div class="mw-translate-fuzzy">
Every new user is automatically created as a Practitioner. Under <i>Administration → User roles</i> you can assign additional roles to users as an Expert or administrator. <p> The page is structured as a large permission matrix, where each row corresponds to a user and each column to a specific module permission. Modules for Experts, Professionals, and Observers are grouped into three large columns. In the screenshot below, you can see three “islands” of assigned checkmarks. [[Datei:Benutzerrollen Zuordnung.png|left|thumb|900px|User role assignment]]<br clear=all>
Under "Administration → User roles" it is possible to assign the respective roles for the desired user.
</div>


<b>Licenses:</b>
<b>Licenses:</b>


<div class="mw-translate-fuzzy">
Licenses control how many and which module roles you can assign to your Experts, Professionals, and Observers. If you assign too many licenses, HITGuard will indicate this in the respective column headers in red font. This makes it easy to see at a glance where you are over- or under-licensed. More information about licenses can be found under [[Special:MyLanguage/Lizenzierung | Administration → Licensing]].
The column headings Experts and Professionals also show how many licenses are currently available and how many are being used. This allows you to see at a glance where you are over-licensed or under-licensed. More information about licenses can be found at [[Special:MyLanguage/Lizenzierung | "Administration → Licensing"]].
</div>


<div class="mw-translate-fuzzy">
The following table provides an overview of the different modules that you can assign to your Experts, Professionals, and Observers. The two core modules are included in every license for Experts and Professionals. Add-on modules must be additionally licensed in order to assign them to users.
<b>Important:</b> Experts and professionals must be assigned to a management system after user role assignment in order to be able to perform their tasks.
[[Datei:Benutzerrollen Zuordnung.png|left|thumb|901px|User role assignment]]<br clear=all>
{| class="wikitable"
{| class="wikitable"
! colspan="3" | <b>Modules for experts, professionals, und observers</b>
! colspan="4" | <b>Modules for Experts, Professionals and Observers</b>
|-
|-
!M&C
|rowspan="2" | Core modules
|Measures and controls
|<b>M&K</b>||Measures and controls||With measures and controls, you can prepare tasks and send them to other users based on workflows.
|part of every license
|-
|-
!RM
|<b>RM</b>||Risk management||In this module, you can collect vulnerabilities via questionnaires, conduct protection needs analyses, and maintain risks or opportunities.
|Risk management
|part of every license
|-
|-
!DS
Here is your wikitable with **only the cell content translated** and **syntax unchanged**:
|Data protection
 
|Add-on
```
|rowspan="6" | Add-on Module
|<b>DS</b>
|Data Protection
|The data protection add-on module allows you to maintain processing activities and DPIAs and thus document your GDPR compliance.
|-
|-
!AM
|<b>AM</b>
|Audit management
|Audit Management
|Add-on
|Audit management is an add-on module. It helps you plan, conduct, and evaluate audits and audit programs
|-  
|-  
!FM
|<b>FM</b>
|Case management
|Case Management
|Add-on
|Case management is an add-on that allows you to process reports. Alternatively, it can be set up as a whistleblowing system.
|-  
|-  
!DM
|<b>DM</b>
|Doc-Management
|Document Management
|Add-on
|Document management allows you to organize the documents and links that you have uploaded in HITGuard.
|-
|-
!ESG
|<b>ESG</b>
|ESG management
|ESG Management
|Add-on
|The ESG module allows you to present impacts and carry out the double materiality analysis
|-
|-
!SRM
|<b>SRM</b>
|Supplier risk management
|Supplier Risk Management
|Add-on
|The SRM module allows you to send assessments to suppliers and thus integrate them into your audit processes.
|}
|}
</div>


<div class="mw-translate-fuzzy">
<b>Role assignment:</b>
<b>Assign:</b>
 
</div>
Only Experts and administrators can access this page, so only these two types of users can assign roles. Administrators can assign any role, while Experts can assign all roles except Administrator and Compliance Manager. If an Expert is already registered as a responsible person for a [[Special:MyLanguage/Managementsysteme|management system]], their “Expert” role cannot be revoked.
<b>Important:</b> Experts, Professionals, and Observers must be assigned to a management system after role assignment. Only then can they access the data and perform their tasks.


<div class="mw-translate-fuzzy">
*Administrators can assign any role.
*Experts can assign all roles except Administrator and Compliance Manager.
*The role "Expert" cannot be withdrawn from persons responsible for a management system as long as they are responsible for at least one management system.
</div>




<div class="mw-translate-fuzzy">
=== Change/reset password ===
=== Change/reset password ===
<b>Caution:</b> Changing a password only works if the local login is active. That means: either there is no Active Directory configured or Local Login is enabled under Global Settings.
If a user uses a username and password to log in, their password can be reset. This only works if the user actually logs in this way, i.e., not via another method (e.g. Active Directory), and if local login is enabled in the [[Special:MyLanguage/Globale_Einstellungen|global settings]]. <p>
Change own password:
Each user can change <i>their own password</i> in their [[Special:MyLanguage/Profil|profile]]. In addition, as an administrator or Expert, you can change the password <i>for another user</i>. To do so, go to Administration → Users, open the desired user, click "Change password" in the bottom right, and then enter and confirm a new password. Note that only administrators can reset the passwords of Experts. <p>
# Click on the profile picture or profile name → Profile.
# click on "Change password" at the bottom right
# Enter old and new password and confirm
Change/reset a password as Administrator or Expert:
# Select the desired user under Administration → User
# click on "Change password" at the bottom right
# enter new password and confirm
: <b>Note:</b> Only administrators can reset passwords of experts. Experts can create and authorize users and they can reset passwords for Professionals and Practitioners. The administrator role can also be assigned to multiple users.
</div>


<span id="Benutzer_deaktivieren"></span>
<span id="Benutzer_deaktivieren"></span>
=== Disable user ===
=== Disable user ===


<div class="mw-translate-fuzzy">
Experts and administrators can deactivate users via the user mask. A deactivated user can no longer be selected in the application.
</div>


<div class="mw-translate-fuzzy">
Experts and administrators can deactivate users via the user form. A deactivated user can no longer be selected in the application. The user is displayed as "deactivated" in management systems and teams in which they are already included. Therefore, not all user assignments need to be removed before the user can be deactivated.
When deactivating, there is the option to anonymize the user in the system.
 
</div>
When deactivating, HITGuard asks whether you want to anonymize the user. If you click “Yes”, all user data is removed, the email is deleted, and the name is replaced with a random string of characters. This cannot be undone! If you click "No" in the dialog, the user is deactivated but not anonymized. In this case, they can be reactivated later.


[[Datei:Profilbild zurücksetzten.png|right|thumb|400px|Reset profile picture]]
[[Datei:Profilbild zurücksetzten.png|right|thumb|400px|Reset profile picture]]
Zeile 221: Zeile 181:
=== Reset profile picture ===
=== Reset profile picture ===


<div class="mw-translate-fuzzy">
Experts and administrators can remove a user's profile picture by clicking the icon next to the profile picture.
Experts and administrators can reset a user's profile picture by clicking the icon next to the profile picture.
</div>


<br clear=all>
<br clear=all>

Aktuelle Version vom 19. Juni 2026, 09:23 Uhr

User roles in HITGuard

HITGuard provides five types of user roles, each with its own permissions and functions. The three classic user roles Practitioner, Professional, and Expert work together in HITGuard on analyses, tasks, and other workflows. Admin users can only perform basic administrative tasks. Observer users can only read and evaluate data in HITGuard, but cannot edit it.

The roles Expert, Professional, and Observer are not assigned as a complete license, but selectively per module. A module is a collection of functions; for example, the risk management module combines all functions for risk analysis. To authorize Experts, Professionals, and Observers, assign licenses to individual users that control which modules they have access to. For example, one user may have access to case management, while another can only work in audit management.

The individual modules or licenses that you can assign to Experts, Professionals, and Observers are explained in this article under “Assigning user roles”.

Practitioner (workflow user)

Menu of a Practitioner user

Practitioners have the fewest permissions in the system. They only see the “My tasks” module, which shows them the tasks they have to complete (and have already completed). Although colleagues with these user accounts are not primarily responsible for the management system, they possess knowledge and skills that the management system requires. It is essential for a living management system that Practitioners share their knowledge with HITGuard experts.

  • A Practitioner has an overview of all measures, controls, reviews, and risks assigned to them.
  • If add-ons are used, they also have access to processing activities or reports
  • HITGuard informs them by email when tasks are waiting for them. They also receive an orange number badge in the “My tasks” module indicating how many tasks are waiting for them (see screenshot).
  • Practitioner is the standard role that every user has. When you create a new user, they are automatically a Practitioner. Apart from the Admin, every other user has the permissions of a Practitioner (for Experts, Professionals, and Observers, the Practitioner license is free).
  • Practitioners do not need to be assigned to modules or management systems. They can receive tasks from all management systems.


Professional

Menu of a Professional user with the risk management module and case management add-on open

Professionals can view, edit, and create data in the management system. In addition, a Professional can do everything a Practitioner can do (see above). Professionals are designed as support for the management system or for Experts.

To view and edit data, Professionals must be added to the management system. They can then create analyses and risks, assign measures and controls, generate reports, and evaluate KPIs in the dashboard.

They can also work in the respective add-on modules. This includes, among other things:

Module Capabilites of a Professional
Audit management

manage Audits and Audit programs.

data protection create processing activities and assign TOMs.
case management work with tickets and add deadlines.
Docu management uploading documents hochladen and editing registries.
ESG management create and edit Impacts.
Supplier Risk Management Sending questionnaires to suppliers.


Expert

Menu of an Expert user with open risk policy. Note the second-to-last module “Administration”.

Expert users are the most powerful role in the system and are therefore intended for managerial functions within the management system. They can do everything that Professionals and Practitioners can do (see above). In addition, Experts can use certain special functions, such as the authorized editing mode. Experts also manage basic settings, management systems, evaluation tools, and master data. For this purpose, Experts have access to the “Administration” module:

basic settings
Expert users can configure basic settings that apply to the entire HITGuard installation in the global settings and the risk policy. Experts also have access to the settings of the respective modules (the screenshot shows the risk management settings as the last item in the open module).

management systems
Just like Professionals, Experts must be added to the management system to view its data. However, Experts can also create and manage management systems. This means that Experts decide, for example, which other users (Experts, Professionals, and Observers) they add to their management system and which they do not.

evaluation tool
In addition, an Expert can use the structural analysis. This is a central modeling tool used to relate and evaluate master data, dependencies, and risks. Learn more about it here.

master data
Work in HITGuard is based on master data and other fundamental data that are managed by Expert users. The following table provides an overview of this data:

Type Menu item Description and core function
Master data organizational units Represent the different departments of an organization.
Resources Represent the IT systems used by the organization.
Data categories Data categories represent the main types of data that are relevant for the organization.
Processes Represent workflows that the organization performs repeatedly.
Suppliers Represent the companies that provide important inputs to the organization, including IT systems.
Knowledge bases Contain templates for questionnaires, tasks, and many other elements.
Standards and norms Used to evaluate compliance with a standard or legal text.
Additional basic data in the Administration module Teams Teams can be used to group multiple users who should complete tasks together.
Text blocks Allow you to create text templates for specific HITGuard functions.
AI prompt management Here you can manage templates for AI prompts if you use an AI integration.
Data import Allows the import of data from Excel files. With this function, you can import risks, measures, master data, and other kinds of data.

Admin

This role only performs administrative tasks, but has no insight into data related to analyses and tasks. Many of these tasks, such as managing management systems, knowledge bases, and users, can also be performed by Experts (see above). Other tasks can only be carried out by an administrator:

  • If an Expert user has lost their password and is locked out, the Admin can reset the password for the Expert. Passwords of other users can also be reset by an Expert. (Note: For this function, the user must log in via password, not via directory service.)
  • The Admin can set up and activate a REST API interface.

Note: When initially setting up a new production system, at least one administrator must be defined. In a SaaS solution, this task can be performed by a TogetherSecure employee; for on-premises setups, the administrator must be provided by your organization.

Observer

Observers see the same data as Professional users (see above), but can only read it, not edit it. Just like a Professional or Expert, the Observer must be added to the management system they should have access to. Observer users (like Professionals and Experts) also have a functional Practitioner module and can therefore process tasks assigned to them.

Observers can not only view data, but also generate reports and adjust and evaluate KPIs on dashboards. Observer roles are suitable for giving management or auditors insight into the management system.

User Administration

Create user


Create user

There are three ways to create a user. When a user is created, they are initially only a Practitioner (see above). Additional roles can then be assigned later (see below)

Manual entry
Under Administration → Users you will find the user list. Here you can add a user by clicking the plus button. You can see the input form in the image on the right. If you choose this method, you should inform the user that the password you set is only an initial password and should be changed in their own profile.

Excel import
Via the menu item Data import, Experts can import user lists. This allows you to create and update users. It is also possible to create a new user by importing another element, e.g. an organizational unit.

Directory service connection
If you have connected a directory service (LDAP or AD/Entra ID), you can create users directly from the directory service. This can be done in two ways:

  • In the image on the right, you can see the field “Search in directory service” at the very top. This is only displayed if a directory service is connected. You can use it to search for a user in your directory service and import the data directly. After that, you still need to
  • In many other elements in the software, you will find user selection fields, e.g. in measures. There you can select users and assign them to elements. If you have connected a directory service, HITGuard will not only suggest users in HITGuard, but also matching entries from the directory service. If you select one of these and save, the user will be imported from the directory service. (Note: Since other users may also have access to these elements, Professionals and, in exceptional cases, Practitioners can also create new users.)

Users created via the directory service can then simply log in with a click on “Sign in with Microsoft” (single sign-on) and no longer need their own HITGuard password. Even if the user was created in another way, every user can independently link their account to the directory service in their profile (provided a directory service is connected to HITGuard).

Assigning user roles

Every new user is automatically created as a Practitioner. Under Administration → User roles you can assign additional roles to users as an Expert or administrator.

The page is structured as a large permission matrix, where each row corresponds to a user and each column to a specific module permission. Modules for Experts, Professionals, and Observers are grouped into three large columns. In the screenshot below, you can see three “islands” of assigned checkmarks.

User role assignment


Licenses:

Licenses control how many and which module roles you can assign to your Experts, Professionals, and Observers. If you assign too many licenses, HITGuard will indicate this in the respective column headers in red font. This makes it easy to see at a glance where you are over- or under-licensed. More information about licenses can be found under Administration → Licensing.

The following table provides an overview of the different modules that you can assign to your Experts, Professionals, and Observers. The two core modules are included in every license for Experts and Professionals. Add-on modules must be additionally licensed in order to assign them to users.

Here is your wikitable with **only the cell content translated** and **syntax unchanged**: ```
Modules for Experts, Professionals and Observers
Core modules M&K Measures and controls With measures and controls, you can prepare tasks and send them to other users based on workflows.
RM Risk management In this module, you can collect vulnerabilities via questionnaires, conduct protection needs analyses, and maintain risks or opportunities.
Add-on Module DS Data Protection The data protection add-on module allows you to maintain processing activities and DPIAs and thus document your GDPR compliance.
AM Audit Management Audit management is an add-on module. It helps you plan, conduct, and evaluate audits and audit programs
FM Case Management Case management is an add-on that allows you to process reports. Alternatively, it can be set up as a whistleblowing system.
DM Document Management Document management allows you to organize the documents and links that you have uploaded in HITGuard.
ESG ESG Management The ESG module allows you to present impacts and carry out the double materiality analysis
SRM Supplier Risk Management The SRM module allows you to send assessments to suppliers and thus integrate them into your audit processes.

Role assignment:

Only Experts and administrators can access this page, so only these two types of users can assign roles. Administrators can assign any role, while Experts can assign all roles except Administrator and Compliance Manager. If an Expert is already registered as a responsible person for a management system, their “Expert” role cannot be revoked. Important: Experts, Professionals, and Observers must be assigned to a management system after role assignment. Only then can they access the data and perform their tasks.


Change/reset password

If a user uses a username and password to log in, their password can be reset. This only works if the user actually logs in this way, i.e., not via another method (e.g. Active Directory), and if local login is enabled in the global settings.

Each user can change their own password in their profile. In addition, as an administrator or Expert, you can change the password for another user. To do so, go to Administration → Users, open the desired user, click "Change password" in the bottom right, and then enter and confirm a new password. Note that only administrators can reset the passwords of Experts.

Disable user

Experts and administrators can deactivate users via the user form. A deactivated user can no longer be selected in the application. The user is displayed as "deactivated" in management systems and teams in which they are already included. Therefore, not all user assignments need to be removed before the user can be deactivated.

When deactivating, HITGuard asks whether you want to anonymize the user. If you click “Yes”, all user data is removed, the email is deleted, and the name is replaced with a random string of characters. This cannot be undone! If you click "No" in the dialog, the user is deactivated but not anonymized. In this case, they can be reactivated later.

Reset profile picture

Reset profile picture

Experts and administrators can remove a user's profile picture by clicking the icon next to the profile picture.