Benutzer und Benutzerrollen/en: Unterschied zwischen den Versionen
Weitere Optionen
KoKl (Diskussion | Beiträge) Keine Bearbeitungszusammenfassung |
KoKl (Diskussion | Beiträge) Keine Bearbeitungszusammenfassung |
||
| Zeile 110: | Zeile 110: | ||
<span id="Benutzerrollen_zuordnen"></span> | <span id="Benutzerrollen_zuordnen"></span> | ||
< | ===<span id="rollen_zuordnen“></span> Assigning user roles === | ||
Version vom 19. Juni 2026, 06:54 Uhr
User roles in HITGuard
HITGuard provides five types of user roles, each with its own permissions and functions. The three classic user roles Practitioner, Professional, and Expert work together in HITGuard on analyses, tasks, and other workflows. Admin users can only perform basic administrative tasks. Observer users can only read and evaluate data in HITGuard, but cannot edit it.
The roles Expert, Professional, and Observer are not assigned as a complete license, but selectively per module. A module is a collection of functions; for example, the risk management module combines all functions for risk analysis. To authorize Experts, Professionals, and Observers, assign licenses to individual users that control which modules they have access to. For example, one user may have access to case management, while another can only work in audit management.
The individual modules or licenses that you can assign to Experts, Professionals, and Observers are explained in this article under “Assigning user roles”.
Practitioner (workflow user)

Practitioners have the fewest permissions in the system. They only see the “My tasks” module, which shows them the tasks they have to complete (and have already completed). Although colleagues with these user accounts are not primarily responsible for the management system, they possess knowledge and skills that the management system requires. It is essential for a living management system that Practitioners share their knowledge with HITGuard experts.
- A Practitioner has an overview of all measures, controls, reviews, and risks assigned to them.
- If add-ons are used, they also have access to processing activities or reports
- HITGuard informs them by email when tasks are waiting for them. They also receive an orange number badge in the “My tasks” module indicating how many tasks are waiting for them (see screenshot).
- Practitioner is the standard role that every user has. When you create a new user, they are automatically a Practitioner. Apart from the Admin, every other user has the permissions of a Practitioner (for Experts, Professionals, and Observers, the Practitioner license is free).
- Practitioners do not need to be assigned to modules or management systems. They can receive tasks from all management systems.
Professional

Professionals can view, edit, and create data in the management system. In addition, a Professional can do everything a Practitioner can do (see above). Professionals are designed as support for the management system or for Experts.
To view and edit data, Professionals must be added to the management system. They can then create analyses and risks, assign measures and controls, generate reports, and evaluate KPIs in the dashboard.
They can also work in the respective add-on modules. This includes, among other things:
| Module | Capabilites of a Professional |
|---|---|
| Audit management |
manage Audits and Audit programs. |
| data protection | create processing activities and assign TOMs. |
| case management | work with tickets and add deadlines. |
| Docu management | uploading documents hochladen and editing registries. |
| ESG management | create and edit Impacts. |
| Supplier Risk Management | Sending questionnaires to suppliers. |
Expert

Expert users are the most powerful role in the system and are therefore intended for managerial functions within the management system. They can do everything that Professionals and Practitioners can do (see above). In addition, Experts can use certain special functions, such as the authorized editing mode. Experts also manage basic settings, management systems, evaluation tools, and master data. For this purpose, Experts have access to the “Administration” module:
basic settings
Expert users can configure basic settings that apply to the entire HITGuard installation in the global settings and the risk policy. Experts also have access to the settings of the respective modules (the screenshot shows the risk management settings as the last item in the open module).
management systems
Just like Professionals, Experts must be added to the management system to view its data. However, Experts can also create and manage management systems. This means that Experts decide, for example, which other users (Experts, Professionals, and Observers) they add to their management system and which they do not.
evaluation tool
In addition, an Expert can use the structural analysis. This is a central modeling tool used to relate and evaluate master data, dependencies, and risks. Learn more about it here.
master data
Work in HITGuard is based on master data and other fundamental data that are managed by Expert users. The following table provides an overview of this data:
| Type | Menu item | Description and core function |
|---|---|---|
| Master data | organizational units | Represent the different departments of an organization. |
| Resources | Represent the IT systems used by the organization. | |
| Data categories | Data categories represent the main types of data that are relevant for the organization. | |
| Processes | Represent workflows that the organization performs repeatedly. | |
| Suppliers | Represent the companies that provide important inputs to the organization, including IT systems. | |
| Knowledge bases | Contain templates for questionnaires, tasks, and many other elements. | |
| Standards and norms | Used to evaluate compliance with a standard or legal text. | |
| Additional basic data in the Administration module | Teams | Teams can be used to group multiple users who should complete tasks together. |
| Text blocks | Allow you to create text templates for specific HITGuard functions. | |
| AI prompt management | Here you can manage templates for AI prompts if you use an AI integration. | |
| Data import | Allows the import of data from Excel files. With this function, you can import risks, measures, master data, and other kinds of data. |
Admin
This role only performs administrative tasks, but has no insight into data related to analyses and tasks. Many of these tasks, such as managing management systems, knowledge bases, and users, can also be performed by Experts (see above). Other tasks can only be carried out by an administrator:
- If an Expert user has lost their password and is locked out, the Admin can reset the password for the Expert. Passwords of other users can also be reset by an Expert. (Note: For this function, the user must log in via password, not via directory service.)
- The Admin can set up and activate a REST API interface.
Note: When initially setting up a new production system, at least one administrator must be defined. In a SaaS solution, this task can be performed by a TogetherSecure employee; for on-premises setups, the administrator must be provided by your organization.
Observer
Observers see the same data as Professional users (see above), but can only read it, not edit it. Just like a Professional or Expert, the Observer must be added to the management system they should have access to. Observer users (like Professionals and Experts) also have a functional Practitioner module and can therefore process tasks assigned to them.
Observers can not only view data, but also generate reports and adjust and evaluate KPIs on dashboards. Observer roles are suitable for giving management or auditors insight into the management system.
User Administration
Create user
There are three ways to create a user. When a user is created, they are initially only a Practitioner (see above). Additional roles can then be assigned later (see below)
Manual entry
Under Administration → Users you will find the user list. Here you can add a user by clicking the plus button. You can see the input form in the image on the right. If you choose this method, you should inform the user that the password you set is only an initial password and should be changed in their own profile.
Excel import
Via the menu item Data import, Experts can import user lists. This allows you to create and update users. It is also possible to create a new user by importing another element, e.g. an organizational unit.
Directory service connection
If you have connected a directory service (LDAP or AD/Entra ID), you can create users directly from the directory service.
This can be done in two ways:
- In the image on the right, you can see the field “Search in directory service” at the very top. This is only displayed if a directory service is connected. You can use it to search for a user in your directory service and import the data directly. After that, you still need to
- In many other elements in the software, you will find user selection fields, e.g. in measures. There you can select users and assign them to elements. If you have connected a directory service, HITGuard will not only suggest users in HITGuard, but also matching entries from the directory service. If you select one of these and save, the user will be imported from the directory service. (Note: Since other users may also have access to these elements, Professionals and, in exceptional cases, Practitioners can also create new users.)
Users created via the directory service can then simply log in with a click on “Sign in with Microsoft” (single sign-on) and no longer need their own HITGuard password. Even if the user was created in another way, every user can independently link their account to the directory service in their profile (provided a directory service is connected to HITGuard).
Assigning user roles
Every new user is automatically created as a Practitioner. Under Administration → User roles you can assign additional roles to users as an Expert or administrator.
The page is structured as a large permission matrix, where each row corresponds to a user and each column to a specific module permission. Modules for Experts, Professionals, and Observers are grouped into three large columns. In the screenshot below, you can see three “islands” of assigned checkmarks.

Licenses:
Licenses control how many and which module roles you can assign to your Experts, Professionals, and Observers. If you assign too many licenses, HITGuard will indicate this in the respective column headers in red font. This makes it easy to see at a glance where you are over- or under-licensed. More information about licenses can be found under Administration → Licensing.
The following table provides an overview of the different modules that you can assign to your Experts, Professionals, and Observers. The two core modules are included in every license for Experts and Professionals. Add-on modules must be additionally licensed in order to assign them to users.
Here is your wikitable with **only the cell content translated** and **syntax unchanged**: ```| Modules for Experts, Professionals and Observers | |||
|---|---|---|---|
| Core modules | M&K | Measures and controls | With measures and controls, you can prepare tasks and send them to other users based on workflows. |
| RM | Risk management | In this module, you can collect vulnerabilities via questionnaires, conduct protection needs analyses, and maintain risks or opportunities. | |
| Add-on Module | <b>DS</b> | Data Protection | The data protection add-on module allows you to maintain processing activities and DPIAs and thus document your GDPR compliance. |
| <b>AM</b> | Audit Management | Audit management is an add-on module. It helps you plan, conduct, and evaluate audits and audit programs | |
| <b>FM</b> | Case Management | Case management is an add-on that allows you to process reports. Alternatively, it can be set up as a whistleblowing system. | |
| <b>DM</b> | Document Management | Document management allows you to organize the documents and links that you have uploaded in HITGuard. | |
| <b>ESG</b> | ESG Management | The ESG module allows you to present impacts and carry out the double materiality analysis | |
| <b>SRM</b> | Supplier Risk Management | The SRM module allows you to send assessments to suppliers and thus integrate them into your audit processes. | |
Role assignment:
Only Experts and administrators can access this page, so only these two types of users can assign roles. Administrators can assign any role, while Experts can assign all roles except Administrator and Compliance Manager. If an Expert is already registered as a responsible person for a management system, their “Expert” role cannot be revoked. Important: Experts, Professionals, and Observers must be assigned to a management system after role assignment. Only then can they access the data and perform their tasks.
Change/reset password
If a user uses a username and password to log in, their password can be reset. This only works if the user actually logs in this way, i.e., not via another method (e.g. Active Directory), and if local login is enabled in the global settings.
Each user can change their own password in their profile. In addition, as an administrator or Expert, you can change the password for another user. To do so, go to Administration → Users, open the desired user, click "Change password" in the bottom right, and then enter and confirm a new password. Note that only administrators can reset the passwords of Experts.
Disable user
Experts and administrators can deactivate users via the user form. A deactivated user can no longer be selected in the application. The user is displayed as "deactivated" in management systems and teams in which they are already included. Therefore, not all user assignments need to be removed before the user can be deactivated.
When deactivating, HITGuard asks whether you want to anonymize the user. If you click “Yes”, all user data is removed, the email is deleted, and the name is replaced with a random string of characters. This cannot be undone! If you click "No" in the dialog, the user is deactivated but not anonymized. In this case, they can be reactivated later.

Reset profile picture
Experts and administrators can remove a user's profile picture by clicking the icon next to the profile picture.