Menü aufrufen
Toggle preferences menu
Persönliches Menü aufrufen
Nicht angemeldet
Ihre IP-Adresse wird öffentlich sichtbar sein, wenn Sie Änderungen vornehmen.

Users and user roles

Aus HITGuard User Guide

User roles in HITGuard

HITGuard provides five types of user roles, each with its own permissions and functions. The three classic user roles Practitioner, Professional, and Expert work together in HITGuard on analyses, tasks, and other workflows. Admin users can only perform basic administrative tasks. Observer users can only read and evaluate data in HITGuard, but cannot edit it.

The roles Expert, Professional, and Observer are not assigned as a complete license, but selectively per module. A module is a collection of functions; for example, the risk management module combines all functions for risk analysis. To authorize Experts, Professionals, and Observers, assign licenses to individual users that control which modules they have access to. For example, one user may have access to case management, while another can only work in audit management.

The individual modules or licenses that you can assign to Experts, Professionals, and Observers are explained in this article under “Assigning user roles”.

Practitioner (workflow user)

Menu of a Practitioner user

Practitioners have the fewest permissions in the system. They only see the “My tasks” module, which shows them the tasks they have to complete (and have already completed). Although colleagues with these user accounts are not primarily responsible for the management system, they possess knowledge and skills that the management system requires. It is essential for a living management system that Practitioners share their knowledge with HITGuard experts.

  • A Practitioner has an overview of all measures, controls, reviews, and risks assigned to them.
  • If add-ons are used, they also have access to processing activities or reports
  • HITGuard informs them by email when tasks are waiting for them. They also receive an orange number badge in the “My tasks” module indicating how many tasks are waiting for them (see screenshot).
  • Practitioner is the standard role that every user has. When you create a new user, they are automatically a Practitioner. Apart from the Admin, every other user has the permissions of a Practitioner (for Experts, Professionals, and Observers, the Practitioner license is free).
  • Practitioners do not need to be assigned to modules or management systems. They can receive tasks from all management systems.


Professional

Users of this role support the experts of the management systems in the fulfillment of their tasks. A professional has access to all tasks in the management systems they are assigned to, but has limited editing rights.

  • Risk management:
    • A Professional can create and manage analyses and risks.
  • Audit management
    • A Professional can create, manage and perform audits/audit programs.
  • Measures and controls.
    • They can create and manage measures and controls.
  • Data Protection
    • A Professional can create processing activities, assign TOMs, and manage externals.
  • Case Management
    • A Professional can process reports and assign periods.
  • Doc-management
    • A Professional can create and edit directories.
    • A Professional can upload and edit files.
  • ESG management
    • A Professional can create and manage impacts and ESG topics.
  • Supplier risk management
    • A Professional can assign a review to a supplier as the interview partner.

Expert

This role may participate in one or more management systems in your organization.

  • Risk management:
    • An Expert can perform analyses and create risks.
    • Experts are responsible for the administration of the risk policy and the risk management settings.
  • Audit management
    • An Expert can create, manage and perform audits/audit programs.
    • Experts are responsible for the administration of audit management settings.
  • Measures and controls
    • An Expert can create and manage measures and controls.
    • Experts are responsible for the administration of the settings in the Progress Monitor.
  • Data protection
    • An Expert can create processing activities, assign TOMs, manage external parties and data subjects.
  • Case management
    • An Expert can process reports and create and manage periods.
    • Experts are responsible for case management settings.
  • Docu management
    • An Expert can create and edit directories.
    • An Expert can upload and edit files.
  • ESG management
    • An Expert an activate and deactivate the menu item.
    • An Expert can create and manage impacts and ESG topics.
  • Supplier risk management
    • An Expert can activate and deactivate the menu item.
    • An Expert can create and manage suppliers.
  • Experts can create and manage management systems.
  • Experts can access the Administration menu and thus also create assets or users.

Admin

This role is responsible for administration as well as for managing other users. Administrators have no insight into data. So, although administrators can manage and create all management systems, they do not have access to their data, nor can they be defined as responsible persons.

  • At the first installation of the software, at least one administrator must be defined.
  • There can be several administrators.
  • Performs purely administrative tasks like creating users and configuring an Active Directory.
  • An admin can import knowledge bases, create a superseding version, and set it as the default version.

Observer

Users of this role have similar permissions as professionals with regard to the visibility of menu items. However, unlike professionals, they cannot make any changes to the system. They have read-only access to the software. To gain visibility into a management system, they must be added to the management system team like a professional or expert.

  • Risk Management:
    • An Observer can view protection needs and vulnerability assessments, risks, measures, and dashboards, and generate reports.
  • Audit Management.
    • An Observer can view audits and audit programs.
  • Measures
    • An Observer can view measures, reports, assessments, and dashboards.
  • Controls
    • An Observer can view controls, reports, and the dashboard.
  • Data protection
    • An Observer can view processing activities and generate reports. TOMs and externals can be viewed without details. Data privacy impact assessments cannot be viewed.
  • Case management
    • An Observer can view reports and periods.
  • Doc-management
    • An Observer can view directories and files.
  • ESG management
    • An Observer can view impacts and ESG topics.

User Administration

Create user

Create user

There are three possibilities to create a user

  • Option 1: Create a user via the user list (for local logins without Active Directory).
Administration → Users: In the user list, on the right margin, click on the button "Plus" to add a user. Then you can create the user with the relevant data.

Note on the interface: "Search in directory service", is only displayed if LDAP is enabled in the global settings and an Active Directory is configured. This allows users to be searched from Active Directory and created with their data in HITGuard.
Note for Azure Active Directory (AAD): Users that were already created before LDAP activation can be linked to their Azure Active Directory account afterwards. This allows to use Single-Sign-On (SSO). This can be done by each user under their profile. (see Profile) Administrators can also load current data from the AAD using a button to the right of the user name. This replaces different information from HITGuard. For this, however, the user must already be linked to an AAD account.
  • Option 2: Quick entry
In the context of use, Active Directory Integration, a new user with minimal permissions for the active module can be created via a person selection screen. To use this, type the person's name or abbreviation in a user selection box. This will load the user from the Active Directory. This user can then log in with his Active Directory data. The user roles can be expanded later, if desired.

Assign user roles

Under "Administration → User roles" it is possible to assign the respective roles for the desired user.

Licenses:

The column headings Experts and Professionals also show how many licenses are currently available and how many are being used. This allows you to see at a glance where you are over-licensed or under-licensed. More information about licenses can be found at "Administration → Licensing".

Important: Experts and professionals must be assigned to a management system after user role assignment in order to be able to perform their tasks.

User role assignment

Modules for experts, professionals, und observers
M&C Measures and controls part of every license
RM Risk management part of every license
DS Data protection Add-on
AM Audit management Add-on
FM Case management Add-on
DM Doc-Management Add-on
ESG ESG management Add-on
SRM Supplier risk management Add-on

Assign:

  • Administrators can assign any role.
  • Experts can assign all roles except Administrator and Compliance Manager.
  • The role "Expert" cannot be withdrawn from persons responsible for a management system as long as they are responsible for at least one management system.


Change/reset password

Caution: Changing a password only works if the local login is active. That means: either there is no Active Directory configured or Local Login is enabled under Global Settings. Change own password:

  1. Click on the profile picture or profile name → Profile.
  2. click on "Change password" at the bottom right
  3. Enter old and new password and confirm

Change/reset a password as Administrator or Expert:

  1. Select the desired user under Administration → User
  2. click on "Change password" at the bottom right
  3. enter new password and confirm
Note: Only administrators can reset passwords of experts. Experts can create and authorize users and they can reset passwords for Professionals and Practitioners. The administrator role can also be assigned to multiple users.

Disable user

Experts and administrators can deactivate users via the user mask. A deactivated user can no longer be selected in the application.

When deactivating, there is the option to anonymize the user in the system.

Reset profile picture

Reset profile picture

Experts and administrators can reset a user's profile picture by clicking the icon next to the profile picture.