Skip to content
English
  • There are no suggestions because the search field is empty.

Roles And Permissions In CyberHQ

How access works in CyberHQ, why the same person can see different things in different workspaces, and what each role can do

What you can see and do in CyberHQ is decided by the roles you hold. This article explains how roles work, why they are granted per workspace rather than once per person, and what each role unlocks.

Roles are held per workspace, not per person. There is no single account-wide permission level. You hold roles inside a specific workspace, and the same person can be an administrator in one workspace and read-only in another. When you switch workspaces, what you can see changes with it. This is deliberate. A workspace exists to separate part of the business, and access separates with it, so someone running your Australian operation does not automatically gain sight of your European one.

A user with no role at all in the workspace they are viewing sees very little: their own tasks and their own settings. That usually means they were invited to CyberHQ but not yet granted access to that particular workspace, which is a separate step from creating the account.

You can hold more than one role. Roles are additive rather than exclusive, so a user who is both an Issue Manager and a Reporting Executive gets both. Most people need two or three rather than one.

How roles behave

Three patterns explain most of the "why can I not see this" questions:

  • Some roles unlock a whole feature. Risk Quantification, for example, is only visible to users holding Risk Assessor. Without it the feature does not appear in the menu at all, which reads as though it is not part of your subscription.

  • Read-only roles hide rather than grey out. An Auditor sees the content and none of the controls, so the page looks cleaner rather than full of things they cannot press.

  • Admin is a superset. An administrator in a workspace reaches everything in it, and is the only role that can assign roles to others.

Notifications follow roles too. Some alerts, such as a Trust Portal access request, go to whoever holds the relevant role rather than to a named person, so leaving a role unfilled can mean nobody is told.

Who can grant a role

Administrators grant roles, and only within their own workspace and the workspaces beneath it. Access flows downward through your workspace hierarchy and never sideways or upward, so an administrator of one division cannot grant themselves access to another.

If you administer a parent workspace you can see who has access to the workspaces below it, but you change that access by switching into the workspace concerned. See User and Workspace Settings Overview.

The Roles

Administration

Role What is it for?
Admin

Full access to everything in the workspace, and the only role that can assign roles to others.

Risk Admin

Manages Risk Settings: the risk matrix, impact types, risk categories and control designations.

Capability Admin

Manages Capability Settings, including uploading frameworks and choosing between subjective and objective scoring.

Assessment

Role What is it for?
Capabilities & Compliance Assessor

Carries out the Capabilities Assessment against your chosen framework, runs Compliance Assessments, and exports results to CSV.

Risk Assessor

Manages the Risk Register and runs Risk Quantification analyses.

Threat Assessor

Builds threat scenarios and runs simulations under Assessments > Threat Modelling.

Catalogue

Role What is it for?
Issue Manager

Creates and manages issues in the Issues Register.

Business System Manager

Views and manages Business Systems and the Business Systems Report.

Security Resources Manager

Views and manages the Security Resources catalogue.

Security Services Manager

Views and manages the Security Services catalogue.

Third Parties & Trust Portal

Role What is it for?
Entity Manager

Uploads and manages questionnaires, sends entity assessments, and accepts or rejects them.

Trust Manager

Manages Trust Portal settings, uploads security resource documents such as certificates, and creates entities.

Programs/Strategy

Role What is it for?

Program Manager

Manages programs and their activities, with access to Manage Program and the Program Dashboard.

Program Contributor

Modifies activities but not the programs containing them.

Program Viewer

Read-only access to programs and the Program Dashboard.

Reporting and Read-Only

Role What is it for?
Reporting Executive

Views the Executive Report.

Reporting Capability

Views the Capabilities Report and can export its charts.

Reporting Risk

Views the risk reporting.

Reporting Threat

Views the Threat FX dashboard.

Auditor

Read-only access to the Capabilities Assessment.


If you cannot see something you expect

Work through these in order:

  1. Check which workspace you are in. The most common cause is being in the wrong one, particularly after following a link from an email or a report.

  2. Ask an administrator which roles you hold in that workspace. They can see this from Settings > Users and change it there.

  3. If you hold the right role and still cannot see the feature, it may not be enabled for your organisation. Raise it with support rather than with your administrator.

Where to go next

To grant or change someone's access, see How to invite and archive users.

For how workspaces relate to one another, see User and Workspace Settings Overview.