Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

Benutzer und Benutzerrollen/en: Unterschied zwischen den Versionen

Aus HITGuard User Guide
Faha (Diskussion | Beiträge)
Keine Bearbeitungszusammenfassung
KoKl (Diskussion | Beiträge)
Keine Bearbeitungszusammenfassung
 
(116 dazwischenliegende Versionen von 6 Benutzern werden nicht angezeigt)
Zeile 1: Zeile 1:


== <span id="user_roles"></span>User-roles in HITGuard ==
<span id="Benutzerrollen_in_HITGuard"></span>
== <span id="user_roles"></span>User roles in HITGuard ==


<div class="mw-translate-fuzzy">
Each user role has its own permissions.<br>
User roles can be given seperately for every modul.<br>
That means a user can be an Expert in the Security Assessor but only an Professional or Practitioner in the Progress Monitor.<br>
[[$PM_user_roles|User-roles in the Progress Monitor]], [[$SA_user_rolse|User-roles in the Security Assessor]]
</div>


HITGuard provides five types of user roles, each with its own permissions and functions. The three classic user roles Practitioner, Professional, and Expert work together in HITGuard on analyses, tasks, and other workflows. Admin users can only perform basic administrative tasks. Observer users can only read and evaluate data in HITGuard, but cannot edit it. <p>
The roles Expert, Professional, and Observer are not assigned as a complete license, but selectively per module. A module is a collection of functions; for example, the risk management module combines all functions for risk analysis. To authorize Experts, Professionals, and Observers, assign licenses to individual users that control which modules they have access to. For example, one user may have access to <i>case management</i>, while another can only work in <i>audit management</i>. <p>
The individual modules or licenses that you can assign to Experts, Professionals, and Observers are explained in this article under “[[#rollen_zuordnen|Assigning user roles]]”.


'''Admin:'''
<span id="Practitioner_(Workflow-Benutzer)"></span>
=== Practitioner (workflow user) ===


Diese Rolle ist für die Administration sowie für die Verwaltung anderer Benutzer zuständig. Administratoren haben keinen Einblick in Daten. Zum Beispiel können Administratoren zwar '''alle''' Managementsysteme verwalten und erstellen, haben aber weder einblick in deren Daten noch können sie als Verantwortliche festgelegt werden.
[[Datei:01Practi.png|right|thumb|400px|Menu of a Practitioner user]] Practitioners have the fewest permissions in the system. They only see the “My tasks” module, which shows them the tasks they have to complete (and have already completed).
* Bei Erstinstallation der Software ist min. ein Administrator zu definieren.
Although colleagues with these user accounts are not primarily responsible for the management system, they possess knowledge and skills that the management system requires. It is essential for a living management system that Practitioners share their knowledge with HITGuard experts. <p>
* Es kann mehrere Administratoren geben.
*A Practitioner has an overview of all measures, controls, reviews, and risks assigned to them.
* Erfüllt rein administrative Aufgaben.
*If add-ons are used, they also have access to processing activities or reports
*HITGuard informs them by email when tasks are waiting for them. They also receive an orange number badge in the “My tasks” module indicating how many tasks are waiting for them (see screenshot).
*Practitioner is the standard role that every user has. When you create a new user, they are automatically a Practitioner. Apart from the Admin, every other user has the permissions of a Practitioner (for Experts, Professionals, and Observers, the Practitioner license is free).
*Practitioners do not need to be assigned to modules or management systems. They can receive tasks from all management systems.
<br clear=all>


<div class="mw-translate-fuzzy">
=== Professional ===
'''Expert:'''<br>
In this role you will be responsible for one or more [[$A_manSys|management systems]] in your company. You must plan measures for findings, ensure the sustainability of these measures and are required to report to Management.
* can create and administrate management systems
* can create assessments, risks, measures and controls and can also administrate findings <br>(expert mode in the Progress Monitor for processing progress reports) 
* is responsible for the administration of the risk policy
* can make access permissions and basic configurations
</div>


Diese Rolle verantwortet ein oder mehrere [[Special:MyLanguage/Managementsysteme|Managementsysteme]] in Ihrem Unternehmen.
* Security Assessor (Risikomanagement):
**Kann Bewertungen, Risiken erstellen und auch Feststellungen administrieren.
** verantwortet die Administration der Risikopolitik
* Progress Monitor (Maßnahmen und Kontrollen)
** Kann Maßnahmen und Kontrollen erstellen und administrieren.
** verantwortet die Administration der Einstellungen im Progress Monitor
* Data Protector (Datenschutz)
** Kann Verarbeitungstätigkeiten erstellen, TOMs zuweisen, Externe und Betroffene administrieren.
* kann Managementsysteme erstellen und verwalten
* Kann die Zugriffsberechtigungen und Basiskonfigurationen vornehmen
* kann die Administration verwalten


[[Datei:02Prof.png|right|thumb|400px|Menu of a Professional user with the risk management module and case management add-on open]] Professionals can view, edit, and create data in the [[Special:MyLanguage/Managementsysteme|management system]]. In addition, a Professional can do everything a Practitioner can do (see above). Professionals are designed as support for the management system or for Experts. <p>
To view and edit data, Professionals must be added to the management system. They can then create [[Special:MyLanguage/Schwachstellen|analyses]] and risks, assign [[Special:MyLanguage/Aktuelle_Maßnahmen|measures]] and [[Special:MyLanguage/Kontrolldefinitionen|controls]], generate reports, and evaluate KPIs in the [[Special:MyLanguage/Risikomanagement_Dashboard|dashboard]]. <p>
They can also work in the respective add-on modules. This includes, among other things:
{|class="wikitable" style="float:right"
!Module !! Capabilites of a Professional
|-
| Audit management ||
manage [[Special:MyLanguage/Auditplanung|Audits]] and Audit programs.
|-
|data protection|| create [[Special:MyLanguage/Verarbeitungsregister|processing activities]] and assign TOMs.
|-
| case management||work with [[Special:MyLanguage/Meldungen|tickets]] and add deadlines.
|-
| Docu management || [[Special:MyLanguage/Dokumentenmanagement|uploading documents hochladen]] and editing registries.
|-
| ESG management || create and edit [[Special:MyLanguage/Auswirkungen|Impacts]].
|-
| Supplier Risk Management||[[Special:MyLanguage/Supplier_Risk_Management|Sending]] questionnaires to suppliers.
|}<br clear=all>


<div class="mw-translate-fuzzy">
=== Expert ===
'''Professional:'''
* has access to all tasks in the management system with limited editing rights
* can create assessments, risks, measures and controls and can also administrate findings
</div>


User dieser Rolle unterstützen die Experten der Managementsysteme in der Erfüllung ihrer Aufgaben. Ein Professional hat Zugriff auf alle Aufgaben, in den Managementsystemen denen er zugeteilt ist, mit eingeschränkten Bearbeitungsrechten
* Security Assessor (Risikomanagement):
**Kann Bewertungen, Risiken erstellen und auch Feststellungen administrieren.
* Progress Monitor (Maßnahmen und Kontrollen)
** Kann Maßnahmen und Kontrollen erstellen und administrieren.
* Data Protector (Datenschutz)
** Kann Verarbeitungstätigkeiten erstellen, TOMs zuweisen und Externe verwalten.


<div class="mw-translate-fuzzy">
[[Datei:02Exp.png|right|thumb|400px|Menu of an Expert user with open risk policy. Note the second-to-last module “Administration”.]] Expert users are the most powerful role in the system and are therefore intended for managerial functions within the management system. They can do everything that Professionals and Practitioners can do (see above). In addition, Experts can use certain special functions, such as the [[Special:MyLanguage/Fortschrittsmeldungen#Eingreifen_in_Fortschrittsmeldungen|authorized editing mode]]. Experts also manage basic settings, management systems, evaluation tools, and master data. For this purpose, Experts have access to the “Administration” module: <p>
'''Practitioner:'''<br>
<b>basic settings</b><br>Expert users can configure basic settings that apply to the entire HITGuard installation in the [[Special:MyLanguage/Globale_Einstellungen|global settings]] and the [[Special:MyLanguage/Risikopolitik|risk policy]]. Experts also have access to the settings of the respective modules (the screenshot shows the risk management settings as the last item in the open module). <p>
In this role, you have detailed information and implementation skills that are required from within the management system. Sharing your knowledge with HITGuard Experts is essential for a vibrant management system.
<b>management systems</b><br> Just like Professionals, Experts must be added to the [[Special:MyLanguage/Managementsysteme|management system]] to view its data. However, Experts can also create and manage [[Special:MyLanguage/Managementsysteme|management systems]]. This means that Experts decide, for example, which other users (Experts, Professionals, and Observers) they add to their management system and which they do not. <p>
* has an overview of all findings, controls and assessments assigned to him for response
<b>evaluation tool</b><br>In addition, an Expert can use the structural analysis. This is a central modeling tool used to relate and evaluate master data, dependencies, and risks. Learn more about it [[Special:MyLanguage/Strukturanalyse|here]].
* will be reminded to complete his tasks
<p>
* is the standard role that each user has over all modules
<b>master data</b><br>Work in HITGuard is based on master data and other fundamental data that are managed by Expert users. The following table provides an overview of this data:
</div>
{|class="wikitable" style="float:right; margin-left:10px; width:900px;"
! style="text-align:left" | Type !! Menu item !! Description and core function
|-
| rowspan="7" | Master data
| [[Special:MyLanguage/OrgEh_-_Organisationseinheiten|organizational units]] || Represent the different departments of an organization.
|-
| [[Special:MyLanguage/Ressourcen|Resources]] || Represent the IT systems used by the organization.
|-
| [[Special:MyLanguage/Datenkategorien|Data categories]] || Data categories represent the main types of data that are relevant for the organization.
|-
| [[Special:MyLanguage/Prozesse|Processes]] || Represent workflows that the organization performs repeatedly.
|-
| [[Special:MyLanguage/Lieferanten|Suppliers]] || Represent the companies that provide important inputs to the organization, including IT systems.
|-
| [[Special:MyLanguage/Wissensdatenbanken|Knowledge bases]] || Contain templates for questionnaires, tasks, and many other elements.
|-
| [[Special:MyLanguage/Standards_und_Normen|Standards and norms]] || Used to evaluate compliance with a standard or legal text.
|-
| rowspan="4" | Additional basic data in the Administration module
| [[Special:MyLanguage/Teams|Teams]] || Teams can be used to group multiple users who should complete tasks together.
|-
| [[Special:MyLanguage/Textbausteine|Text blocks]] || Allow you to create text templates for specific HITGuard functions.
|-
| [[Special:MyLanguage/KI-Promptverwaltung|AI prompt management]] || Here you can manage templates for AI prompts if you use an AI integration.
|-
| [[Special:MyLanguage/Datenimport|Data import]] || Allows the import of data from Excel files. With this function, you can import risks, measures, master data, and other kinds of data.
|}


Diese Rolle verfügt über Detailinformationen und Umsetzungskompetenzen die aus dem Managementsystem heraus benötigt werden. Dass Practitioner ihr Wissen mit den HITGuard Experten teilen ist für ein lebendiges Managementsystem unbedingt erforderlich.
=== Admin ===
* hat Überblick über alle ihm zugeteilten Maßnahmen, Kontrollen, Verarbeitungstätigkeiten und Bewertungen zur Beantwortung
* wird an die Erledigung seiner Aufgaben erinnert
* ist die Standardrolle die jeder Benutzer modulübergreifend besitzt.


This role only performs administrative tasks, but has no insight into data related to analyses and tasks. Many of these tasks, such as managing [[Special:MyLanguage/Managementsysteme|management systems]], [[Special:MyLanguage/Wissensdatenbanken|knowledge bases]], and users, can also be performed by Experts (see above). Other tasks can only be carried out by an administrator:
*If an Expert user has lost their password and is locked out, the Admin can reset the password for the Expert. Passwords of other users can also be reset by an Expert. (Note: For this function, the user must log in via password, not via directory service.)
*The Admin can set up and activate a [[Special:MyLanguage/Datenimport/-export_Schnittstelle|REST API]] interface. <p>
<b>Note</b>: When initially setting up a new production system, at least one administrator must be defined. In a SaaS solution, this task can be performed by a TogetherSecure employee; for on-premises setups, the administrator must be provided by your organization.
<span id="Observer_(Beobachter)"></span>
=== Observer ===
Observers see the same data as Professional users (see above), but can only read it, not edit it. Just like a Professional or Expert, the Observer must be added to the [[Special:MyLanguage/Managementsysteme|management system]] they should have access to. Observer users (like Professionals and Experts) also have a functional Practitioner module and can therefore process tasks assigned to them. <p>
Observers can not only view data, but also generate reports and adjust and evaluate KPIs on dashboards. Observer roles are suitable for giving management or auditors insight into the management system.
<span id="Benutzerverwaltung"></span>
== User Administration ==
== User Administration ==


<div class="mw-translate-fuzzy">
[[Datei:Benutzer anlegen.PNG|thumb|right|500px|Create user]]
Creating a new user is divided into 3 steps:
 
# Create user including initial password:
 
#:There are 2 ways to create a user
=== Create user ===
#:* Option 1: Userlist
There are three ways to create a user. When a user is created, they are initially only a Practitioner (see above). Additional roles can then be assigned later (see below) <p>
#::: Administration ==> User
<b>Manual entry</b> <br> Under <i> Administration → Users </i> you will find the user list. Here you can add a user by clicking the plus button. You can see the input form in the image on the right. If you choose this method, you should inform the user that the password you set is only an initial password and should be changed in their own [[Special:MyLanguage/Profil|profile]]. <p>
#::: In the userlist click on the plus button "Create user"<br>and create the user with all relevant Data.(see [[Profil|Profil]]).
<b>Excel import</b> <br> Via the menu item [[Special:MyLanguage/Datenimport|Data import]], Experts can import user lists. This allows you to create and update users. It is also possible to create a new user by importing another element, e.g. an organizational unit. <p>
#:* Option 2: fast entry
<b>Directory service connection</b> <br> If you have connected a directory service (LDAP or AD/Entra ID), you can create users directly from the directory service.
#::: In the context of use, Active Directory Integration can be used to create a new user with minimal permissions via a person selection mask. E.g. when creating measures
This can be done in two ways:
# User role allocation:
*In the image on the right, you can see the field “Search in directory service” at the very top. This is only displayed if a directory service is connected. You can use it to search for a user in your directory service and import the data directly. After that, you still need to
#: User roles can only be assigned by Administrators or Exoerts.<br>For this go to "Administration ==> user-role-assignment" and assign the respective roles to the desired user.<br>Important: Experts and Professionals need to be assigned to a management system in order to complete their tasks.[[Benutzer zu Managementsystemen zuteilen|Assigning Users to Management Systems]]
*In many other elements in the software, you will find user selection fields, e.g. in measures. There you can select users and assign them to elements. If you have connected a directory service, HITGuard will not only suggest users in HITGuard, but also matching entries from the directory service. If you select one of these and save, the user will be imported from the directory service. (<b>Note:</b> Since other users may also have access to these elements, Professionals and, in exceptional cases, Practitioners can also create new users.)
# Change passwords:
Users created via the directory service can then simply [[Special:MyLanguage/Login_Möglichkeiten|log in]] with a click on “Sign in with Microsoft” (single sign-on) and no longer need their own HITGuard password. Even if the user was created in another way, every user can independently link their account to the directory service in their [[Special:MyLanguage/Profil|profile]] (provided a directory service is connected to HITGuard). <p>
#: Change your own password:
 
#:# Click on the profile picture or the profile name.
<span id="Benutzerrollen_zuordnen"></span>
#:# click on "Change password" in the bottom right corner
===<span id="rollen_zuordnen“></span> Assigning user roles ===
#:# Enter the old and new password and confirm
 
#: Change a password as an Administrator or Expert:
 
#:# go to "Administration ==> user" and select the desired user
Every new user is automatically created as a Practitioner. Under <i>Administration → User roles</i> you can assign additional roles to users as an Expert or administrator. <p> The page is structured as a large permission matrix, where each row corresponds to a user and each column to a specific module permission. Modules for Experts, Professionals, and Observers are grouped into three large columns. In the screenshot below, you can see three “islands” of assigned checkmarks. [[Datei:Benutzerrollen Zuordnung.png|left|thumb|900px|User role assignment]]<br clear=all>
#:# click on "Change password" in the bottom right corner
 
#:# Enter the new password and confirm
<b>Licenses:</b>
</div>
 
Licenses control how many and which module roles you can assign to your Experts, Professionals, and Observers. If you assign too many licenses, HITGuard will indicate this in the respective column headers in red font. This makes it easy to see at a glance where you are over- or under-licensed. More information about licenses can be found under [[Special:MyLanguage/Lizenzierung | Administration → Licensing]].
 
The following table provides an overview of the different modules that you can assign to your Experts, Professionals, and Observers. The two core modules are included in every license for Experts and Professionals. Add-on modules must be additionally licensed in order to assign them to users.
{| class="wikitable"
! colspan="4" | <b>Modules for Experts, Professionals and Observers</b>
|-
|rowspan="2" | Core modules
|<b>M&K</b>||Measures and controls||With measures and controls, you can prepare tasks and send them to other users based on workflows.
|-
|<b>RM</b>||Risk management||In this module, you can collect vulnerabilities via questionnaires, conduct protection needs analyses, and maintain risks or opportunities.
|-
Here is your wikitable with **only the cell content translated** and **syntax unchanged**:
 
```
|rowspan="6" | Add-on Module
|<b>DS</b>
|Data Protection
|The data protection add-on module allows you to maintain processing activities and DPIAs and thus document your GDPR compliance.
|-
|<b>AM</b>
|Audit Management
|Audit management is an add-on module. It helps you plan, conduct, and evaluate audits and audit programs
|-
|<b>FM</b>
|Case Management
|Case management is an add-on that allows you to process reports. Alternatively, it can be set up as a whistleblowing system.
|-
|<b>DM</b>
|Document Management
|Document management allows you to organize the documents and links that you have uploaded in HITGuard.
|-
|<b>ESG</b>
|ESG Management
|The ESG module allows you to present impacts and carry out the double materiality analysis
|-
|<b>SRM</b>
|Supplier Risk Management
|The SRM module allows you to send assessments to suppliers and thus integrate them into your audit processes.
|}
 
<b>Role assignment:</b>
 
Only Experts and administrators can access this page, so only these two types of users can assign roles. Administrators can assign any role, while Experts can assign all roles except Administrator and Compliance Manager. If an Expert is already registered as a responsible person for a [[Special:MyLanguage/Managementsysteme|management system]], their “Expert” role cannot be revoked.
<b>Important:</b> Experts, Professionals, and Observers must be assigned to a management system after role assignment. Only then can they access the data and perform their tasks.
 
 
 
=== Change/reset password ===
If a user uses a username and password to log in, their password can be reset. This only works if the user actually logs in this way, i.e., not via another method (e.g. Active Directory), and if local login is enabled in the [[Special:MyLanguage/Globale_Einstellungen|global settings]]. <p>
Each user can change <i>their own password</i> in their [[Special:MyLanguage/Profil|profile]]. In addition, as an administrator or Expert, you can change the password <i>for another user</i>. To do so, go to Administration → Users, open the desired user, click "Change password" in the bottom right, and then enter and confirm a new password. Note that only administrators can reset the passwords of Experts. <p>
 
<span id="Benutzer_deaktivieren"></span>
=== Disable user ===
 
 
Experts and administrators can deactivate users via the user form. A deactivated user can no longer be selected in the application. The user is displayed as "deactivated" in management systems and teams in which they are already included. Therefore, not all user assignments need to be removed before the user can be deactivated.
 
When deactivating, HITGuard asks whether you want to anonymize the user. If you click “Yes”, all user data is removed, the email is deleted, and the name is replaced with a random string of characters. This cannot be undone! If you click "No" in the dialog, the user is deactivated but not anonymized. In this case, they can be reactivated later.
 
[[Datei:Profilbild zurücksetzten.png|right|thumb|400px|Reset profile picture]]
 
<span id="Profilbild_zurücksetzen"></span>
=== Reset profile picture ===
 
Experts and administrators can remove a user's profile picture by clicking the icon next to the profile picture.
 
<br clear=all>

Aktuelle Version vom 19. Juni 2026, 09:23 Uhr

User roles in HITGuard

HITGuard provides five types of user roles, each with its own permissions and functions. The three classic user roles Practitioner, Professional, and Expert work together in HITGuard on analyses, tasks, and other workflows. Admin users can only perform basic administrative tasks. Observer users can only read and evaluate data in HITGuard, but cannot edit it.

The roles Expert, Professional, and Observer are not assigned as a complete license, but selectively per module. A module is a collection of functions; for example, the risk management module combines all functions for risk analysis. To authorize Experts, Professionals, and Observers, assign licenses to individual users that control which modules they have access to. For example, one user may have access to case management, while another can only work in audit management.

The individual modules or licenses that you can assign to Experts, Professionals, and Observers are explained in this article under “Assigning user roles”.

Practitioner (workflow user)

Menu of a Practitioner user

Practitioners have the fewest permissions in the system. They only see the “My tasks” module, which shows them the tasks they have to complete (and have already completed). Although colleagues with these user accounts are not primarily responsible for the management system, they possess knowledge and skills that the management system requires. It is essential for a living management system that Practitioners share their knowledge with HITGuard experts.

  • A Practitioner has an overview of all measures, controls, reviews, and risks assigned to them.
  • If add-ons are used, they also have access to processing activities or reports
  • HITGuard informs them by email when tasks are waiting for them. They also receive an orange number badge in the “My tasks” module indicating how many tasks are waiting for them (see screenshot).
  • Practitioner is the standard role that every user has. When you create a new user, they are automatically a Practitioner. Apart from the Admin, every other user has the permissions of a Practitioner (for Experts, Professionals, and Observers, the Practitioner license is free).
  • Practitioners do not need to be assigned to modules or management systems. They can receive tasks from all management systems.


Professional

Menu of a Professional user with the risk management module and case management add-on open

Professionals can view, edit, and create data in the management system. In addition, a Professional can do everything a Practitioner can do (see above). Professionals are designed as support for the management system or for Experts.

To view and edit data, Professionals must be added to the management system. They can then create analyses and risks, assign measures and controls, generate reports, and evaluate KPIs in the dashboard.

They can also work in the respective add-on modules. This includes, among other things:

Module Capabilites of a Professional
Audit management

manage Audits and Audit programs.

data protection create processing activities and assign TOMs.
case management work with tickets and add deadlines.
Docu management uploading documents hochladen and editing registries.
ESG management create and edit Impacts.
Supplier Risk Management Sending questionnaires to suppliers.


Expert

Menu of an Expert user with open risk policy. Note the second-to-last module “Administration”.

Expert users are the most powerful role in the system and are therefore intended for managerial functions within the management system. They can do everything that Professionals and Practitioners can do (see above). In addition, Experts can use certain special functions, such as the authorized editing mode. Experts also manage basic settings, management systems, evaluation tools, and master data. For this purpose, Experts have access to the “Administration” module:

basic settings
Expert users can configure basic settings that apply to the entire HITGuard installation in the global settings and the risk policy. Experts also have access to the settings of the respective modules (the screenshot shows the risk management settings as the last item in the open module).

management systems
Just like Professionals, Experts must be added to the management system to view its data. However, Experts can also create and manage management systems. This means that Experts decide, for example, which other users (Experts, Professionals, and Observers) they add to their management system and which they do not.

evaluation tool
In addition, an Expert can use the structural analysis. This is a central modeling tool used to relate and evaluate master data, dependencies, and risks. Learn more about it here.

master data
Work in HITGuard is based on master data and other fundamental data that are managed by Expert users. The following table provides an overview of this data:

Type Menu item Description and core function
Master data organizational units Represent the different departments of an organization.
Resources Represent the IT systems used by the organization.
Data categories Data categories represent the main types of data that are relevant for the organization.
Processes Represent workflows that the organization performs repeatedly.
Suppliers Represent the companies that provide important inputs to the organization, including IT systems.
Knowledge bases Contain templates for questionnaires, tasks, and many other elements.
Standards and norms Used to evaluate compliance with a standard or legal text.
Additional basic data in the Administration module Teams Teams can be used to group multiple users who should complete tasks together.
Text blocks Allow you to create text templates for specific HITGuard functions.
AI prompt management Here you can manage templates for AI prompts if you use an AI integration.
Data import Allows the import of data from Excel files. With this function, you can import risks, measures, master data, and other kinds of data.

Admin

This role only performs administrative tasks, but has no insight into data related to analyses and tasks. Many of these tasks, such as managing management systems, knowledge bases, and users, can also be performed by Experts (see above). Other tasks can only be carried out by an administrator:

  • If an Expert user has lost their password and is locked out, the Admin can reset the password for the Expert. Passwords of other users can also be reset by an Expert. (Note: For this function, the user must log in via password, not via directory service.)
  • The Admin can set up and activate a REST API interface.

Note: When initially setting up a new production system, at least one administrator must be defined. In a SaaS solution, this task can be performed by a TogetherSecure employee; for on-premises setups, the administrator must be provided by your organization.

Observer

Observers see the same data as Professional users (see above), but can only read it, not edit it. Just like a Professional or Expert, the Observer must be added to the management system they should have access to. Observer users (like Professionals and Experts) also have a functional Practitioner module and can therefore process tasks assigned to them.

Observers can not only view data, but also generate reports and adjust and evaluate KPIs on dashboards. Observer roles are suitable for giving management or auditors insight into the management system.

User Administration

Create user


Create user

There are three ways to create a user. When a user is created, they are initially only a Practitioner (see above). Additional roles can then be assigned later (see below)

Manual entry
Under Administration → Users you will find the user list. Here you can add a user by clicking the plus button. You can see the input form in the image on the right. If you choose this method, you should inform the user that the password you set is only an initial password and should be changed in their own profile.

Excel import
Via the menu item Data import, Experts can import user lists. This allows you to create and update users. It is also possible to create a new user by importing another element, e.g. an organizational unit.

Directory service connection
If you have connected a directory service (LDAP or AD/Entra ID), you can create users directly from the directory service. This can be done in two ways:

  • In the image on the right, you can see the field “Search in directory service” at the very top. This is only displayed if a directory service is connected. You can use it to search for a user in your directory service and import the data directly. After that, you still need to
  • In many other elements in the software, you will find user selection fields, e.g. in measures. There you can select users and assign them to elements. If you have connected a directory service, HITGuard will not only suggest users in HITGuard, but also matching entries from the directory service. If you select one of these and save, the user will be imported from the directory service. (Note: Since other users may also have access to these elements, Professionals and, in exceptional cases, Practitioners can also create new users.)

Users created via the directory service can then simply log in with a click on “Sign in with Microsoft” (single sign-on) and no longer need their own HITGuard password. Even if the user was created in another way, every user can independently link their account to the directory service in their profile (provided a directory service is connected to HITGuard).

Assigning user roles

Every new user is automatically created as a Practitioner. Under Administration → User roles you can assign additional roles to users as an Expert or administrator.

The page is structured as a large permission matrix, where each row corresponds to a user and each column to a specific module permission. Modules for Experts, Professionals, and Observers are grouped into three large columns. In the screenshot below, you can see three “islands” of assigned checkmarks.

User role assignment


Licenses:

Licenses control how many and which module roles you can assign to your Experts, Professionals, and Observers. If you assign too many licenses, HITGuard will indicate this in the respective column headers in red font. This makes it easy to see at a glance where you are over- or under-licensed. More information about licenses can be found under Administration → Licensing.

The following table provides an overview of the different modules that you can assign to your Experts, Professionals, and Observers. The two core modules are included in every license for Experts and Professionals. Add-on modules must be additionally licensed in order to assign them to users.

Here is your wikitable with **only the cell content translated** and **syntax unchanged**: ```
Modules for Experts, Professionals and Observers
Core modules M&K Measures and controls With measures and controls, you can prepare tasks and send them to other users based on workflows.
RM Risk management In this module, you can collect vulnerabilities via questionnaires, conduct protection needs analyses, and maintain risks or opportunities.
Add-on Module DS Data Protection The data protection add-on module allows you to maintain processing activities and DPIAs and thus document your GDPR compliance.
AM Audit Management Audit management is an add-on module. It helps you plan, conduct, and evaluate audits and audit programs
FM Case Management Case management is an add-on that allows you to process reports. Alternatively, it can be set up as a whistleblowing system.
DM Document Management Document management allows you to organize the documents and links that you have uploaded in HITGuard.
ESG ESG Management The ESG module allows you to present impacts and carry out the double materiality analysis
SRM Supplier Risk Management The SRM module allows you to send assessments to suppliers and thus integrate them into your audit processes.

Role assignment:

Only Experts and administrators can access this page, so only these two types of users can assign roles. Administrators can assign any role, while Experts can assign all roles except Administrator and Compliance Manager. If an Expert is already registered as a responsible person for a management system, their “Expert” role cannot be revoked. Important: Experts, Professionals, and Observers must be assigned to a management system after role assignment. Only then can they access the data and perform their tasks.


Change/reset password

If a user uses a username and password to log in, their password can be reset. This only works if the user actually logs in this way, i.e., not via another method (e.g. Active Directory), and if local login is enabled in the global settings.

Each user can change their own password in their profile. In addition, as an administrator or Expert, you can change the password for another user. To do so, go to Administration → Users, open the desired user, click "Change password" in the bottom right, and then enter and confirm a new password. Note that only administrators can reset the passwords of Experts.

Disable user

Experts and administrators can deactivate users via the user form. A deactivated user can no longer be selected in the application. The user is displayed as "deactivated" in management systems and teams in which they are already included. Therefore, not all user assignments need to be removed before the user can be deactivated.

When deactivating, HITGuard asks whether you want to anonymize the user. If you click “Yes”, all user data is removed, the email is deleted, and the name is replaced with a random string of characters. This cannot be undone! If you click "No" in the dialog, the user is deactivated but not anonymized. In this case, they can be reactivated later.

Reset profile picture

Reset profile picture

Experts and administrators can remove a user's profile picture by clicking the icon next to the profile picture.