Roles, responsibilities and notifications

When a user is created in the IT settings, one or more roles can be assigned to them. Depending on the role, users have different rights within the Priverion platform. We will go into this in more detail in this article.

Create a new user

In the IT Settings, under the User Management tab, you will see a list of all users of your Priverion platform. You can edit their details by clicking on an individual user or create a new user login by clicking the Create button. When creating a user, you enter their name and email. If you want to notify the user of his new account and ask him to set a password, select send invite per email. The telephone number is optional. Finally, you assign roles to this user.

Roles

While all registered users (who by default have the employee role) can access the dashboard and user settings and view the dashboard charts, other rights are restricted to specific roles. An additional distinction is made between read-only or read-and-write rights. Below, we provide a list of the rights for each role. You can create new roles under IT Settings > Roles. Name the role and assign permissions by selecting the appropriate checkboxes. Once done, Save your input.

If you want to give access (read or write) to a specific element (such as a ROPA, Vendor, etc.), you can do this via the Manage Access menu in each element on the upper right (the three ...). You can also create audiences for this. Learn more here.

Here is a summary PDF of the roles: PRIVERION Platform Roles

Data Protection Manager

Access to dashboardData subject request: read
User settingsAssessment builder: read
Dashboard charts: readCompliance settings: write, read
Data protection impact assessment: write, readSharing: write, read
Process risk: readNotifications: write, read
Projects: write, readOrganizational units: write, read
Documents & Policies: write, readTags: write, read
Assessments: write, readApplicable laws: write, read
TOMs: write, readAudiences: write, read
International standards: write, readIT settings: write, read
Report Explorer: write, readActive Directory: write, read
ROPA: write, readLanguage: write, read
Vendors: write, readUser management: write, read
Legitimate interest documentation: write, readRisk settings: write, read
Meetings & Activities: write, readRisk scenarios: write, read
Retentions & Deletions: write, readPersonal data: write, read
Data collection points: write, readNotes: write, read
Tasks: write, read 

Data Protection Coordinator

Access to dashboardVendors: write, read
User settingsLegitimate interest documentation: write, read
Dashboard charts: readMeetings & Activities: write, read
Data protection impact assessment: write, readRetentions & Deletions: write, rad
Process risk: readData collection points: write, read
Projects: write, readTasks: write, read
Documents & Policies: write, readAssessment builder: read
Assessments: write, readRisk settings: write, read
TOMs: write, readRisk scenarios: write, read
Asset register: write, readPersonal data: write, read
International standards: write, readAudiences: write, read (but no permissions to enter IT settings)
ROPA: write, readNotes: write, read

IT Administrator

Access to dashboardLanguage: write, read
User settingsUser management: write, read
Dashboard charts: readPersonal data: write, read
IT settings: write, readNotes: write, read
Active Directory: write, read 

IT Security Manager

Access to dashboardData collection points: write, read
User settingsTasks: write, read
Dashboard charts: readData subject request: read
Data Protection Impact Assessment: write, readAssessment builder: read
Process risk: readCompliance settings: write, read
Projects: write, readNotifications: write, read
Risk settings: write, readOrganizational units: write, read
Risk scenarios: write, readTags: write, read
Documents & Policies: write, readApplicable laws: write, read
Assessments: write, readCompanies: write, read
TOMs: write, readIT settings:
Assets register: write, readActive Directory: write, read
International standards: write, readLanguage: write, read
ROPA: write, readUser management: write, read
Vendors: write, readPersonal data: write, read
Legitimate interest documentation: write, readNotes: write, read
Meetings & Activities: write, readReport Explorer: write, read
Retentions & Deletions: write, read 

IT Security Coordinator

Access to dashboardInternational standards: write, read
User settingsVendors: write, read
Dashboard charts: readMeetings & Activities: write, read
Projects: write, readTasks: write, read
Documents & Policies: write, readAssessment builder: read
Assessments: write, readRisk settings: write, read
TOMs: write, readPersonal data: write, read
Assets register: write, readNotes: write, read

Employee

Access to dashboardDashboard charts: read
User settingsAny Element: write, read. If the element is assigned to the user as responsible person or if the user is assigned to an audience which has read or write access to the element.

 


 

Was this article helpful?