Users and roles #
Available Reserved for administratorsPurpose and permissions #
From Settings → Users, the administrator manages the accounts of his organization. The fields are first name, last name, email, initial password, roles and status.
Create, modify, deactivate #
Create an account with a unique address and the minimum roles required. A modification adjusts identity, roles or activity. Deletion makes sense: prefer deactivation to preserve the assignments. The available roles follow the hierarchy Admin, Risk manager, Auditor and Action manager.
Research, errors and practices #
Filter the list before editing. An identifier from another tenant is refused. Do not share accounts; Enforce a strong initial password and then prompt the user to enable MFA.
See also #
Profile, MFA and sessions · Audit log
Role matrix #
| Role | Primary Responsibility |
|---|---|
| Super Admin | several organizations |
| Administrator | tenant accounts and settings |
| Risk manager | inventory, risks and treatments |
| Listener | insurance and authorized consultation |
| Responsible for action | execution of assigned actions |
Complete procedure #
Open Settings → Users, enter first name, last name, email and initial password, then assign the minimum roles. Activate the account, register and request a password change with MFA activation.
Before deactivation, reassign risks, actions, documents and deadlines. Logical deletion retains historical responsibilities; never reuse an account for another person.
Checks and errors #
An address already in use requires searching for the existing account. An invisible user can belong to another tenant or be inactive. For an impossible connection, successively check status, lock, password, MFA and sessions.
Example: an audit consultant receives Auditor, not Administrator. A Remediation Manager receives Action Manager.