Users and user roles
Weitere Optionen
User roles in HITGuard
HITGuard provides five types of user roles, each with its own permissions and functions. The three classic user roles Practitioner, Professional, and Expert work together in HITGuard on analyses, tasks, and other workflows. Admin users can only perform basic administrative tasks. Observer users can only read and evaluate data in HITGuard, but cannot edit it.
The roles Expert, Professional, and Observer are not assigned as a complete license, but selectively per module. A module is a collection of functions; for example, the risk management module combines all functions for risk analysis. To authorize Experts, Professionals, and Observers, assign licenses to individual users that control which modules they have access to. For example, one user may have access to case management, while another can only work in audit management.
The individual modules or licenses that you can assign to Experts, Professionals, and Observers are explained in this article under “Assigning user roles”.
Practitioner (workflow user)

Practitioners have the fewest permissions in the system. They only see the “My tasks” module, which shows them the tasks they have to complete (and have already completed). Although colleagues with these user accounts are not primarily responsible for the management system, they possess knowledge and skills that the management system requires. It is essential for a living management system that Practitioners share their knowledge with HITGuard experts.
- A Practitioner has an overview of all measures, controls, reviews, and risks assigned to them.
- If add-ons are used, they also have access to processing activities or reports
- HITGuard informs them by email when tasks are waiting for them. They also receive an orange number badge in the “My tasks” module indicating how many tasks are waiting for them (see screenshot).
- Practitioner is the standard role that every user has. When you create a new user, they are automatically a Practitioner. Apart from the Admin, every other user has the permissions of a Practitioner (for Experts, Professionals, and Observers, the Practitioner license is free).
- Practitioners do not need to be assigned to modules or management systems. They can receive tasks from all management systems.
Professional

Professionals can view, edit, and create data in the management system. In addition, a Professional can do everything a Practitioner can do (see above). Professionals are designed as support for the management system or for Experts.
To view and edit data, Professionals must be added to the management system. They can then create analyses and risks, assign measures and controls, generate reports, and evaluate KPIs in the dashboard.
They can also work in the respective add-on modules. This includes, among other things:
| Module | Capabilites of a Professional |
|---|---|
| Audit management |
manage Audits and Audit programs. |
| data protection | create processing activities and assign TOMs. |
| case management | work with tickets and add deadlines. |
| Docu management | uploading documents hochladen and editing registries. |
| ESG management | create and edit Impacts. |
| Supplier Risk Management | Sending questionnaires to suppliers. |
Expert

basic settings
Expert users can configure basic settings that apply to the entire HITGuard installation in the global settings and the risk policy. Experts also have access to the settings of the respective modules (the screenshot shows the risk management settings as the last item in the open module).
management systems
Just like Professionals, Experts must be added to the management system to view its data. However, Experts can also create and manage management systems. This means that Experts decide, for example, which other users (Experts, Professionals, and Observers) they add to their management system and which they do not.
evaluation tool
In addition, an Expert can use the structural analysis. This is a central modeling tool used to relate and evaluate master data, dependencies, and risks. Learn more about it here.
master data
Work in HITGuard is based on master data and other fundamental data that are managed by Expert users. The following table provides an overview of this data:
| Type | Menu item | Description and core function | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Master data | organizational units | Represent the different departments of an organization. | |||||||||||||
| Resources | Represent the IT systems used by the organization. | ||||||||||||||
| Data categories | Data categories represent the main types of data that are relevant for the organization. | ||||||||||||||
| Processes | Represent workflows that the organization performs repeatedly. | ||||||||||||||
| Suppliers | Represent the companies that provide important inputs to the organization, including IT systems. | ||||||||||||||
| Knowledge bases | Contain templates for questionnaires, tasks, and many other elements. | ||||||||||||||
| Standards and norms | Used to evaluate compliance with a standard or legal text. | ||||||||||||||
| Additional basic data in the Administration module | Teams | Teams can be used to group multiple users who should complete tasks together. | |||||||||||||
| Text blocks | Allow you to create text templates for specific HITGuard functions. | ||||||||||||||
| AI prompt management | Here you can manage templates for AI prompts if you use an AI integration. | ||||||||||||||
| Data import | Allows the import of data from Excel files. With this function, you can import risks, measures, master data, and much more.
AdminThis role only performs administrative tasks, but has no insight into data related to analyses and tasks. Many of these tasks, such as managing management systems, knowledge bases, and users, can also be performed by Experts (see above). Other tasks can only be carried out by an administrator:
Note: When initially setting up a new production system, at least one administrator must be defined. In a SaaS solution, this task can be performed by a TogetherSecure employee; for on-premises setups, the administrator must be provided by your organization.
ObserverObservers can not only view data, but also generate reports and adjust and evaluate KPIs on dashboards. Observer roles are suitable for giving management or auditors insight into the management system. User Administration
Create user
Manual entry
Excel import
Directory service connection
Assign user roles
The page is structured as a large permission matrix, where each row corresponds to a user and each column to a specific module permission. Modules for Experts, Professionals, and Observers are grouped into three large columns. In the screenshot below, you can see three “islands” of assigned checkmarks. ![]() Licenses: Licenses control how many and which module roles you can assign to your Experts, Professionals, and Observers. If you assign too many licenses, HITGuard will indicate this in the respective column headers in red font. This makes it easy to see at a glance where you are over- or under-licensed. More information about licenses can be found under Administration → Licensing. The following table provides an overview of the different modules that you can assign to your Experts, Professionals, and Observers. The two core modules are included in every license for Experts and Professionals. Add-on modules must be additionally licensed in order to assign them to users.
|
||||||||||||||

