Employee portal

Assigned to each person,
nothing else in view.

Employees open the portal and see what is theirs: a policy to acknowledge, a training to complete, a checklist to run, a document to file, the checks on their own laptop. Anything not assigned to them reads as not found, so the rest of the ISMS stays out of view.

Start for freeBook a conversation
++++
app.devguard.ch / portal
Signed in as employee
JL
Jordan Lee
Employee · portal only
Policies1
Trainings1
Tasks2
Processes1
Documents
Evidence
Devices1
Incidents
Good morning, Jordan
Four things are waiting for you, one due today
Done6 of 10
Up next
Acceptable use policy v3
Policydue today
Read and confirm
Security awareness 2026
Trainingdue in 9 days
Start
Monthly server-room walkthrough
Checklist6 of 14 rows
Continue
Screen lock on your MacBook
Deviceoverdue
Fix
Only what is assigned to Jordan appears here. The rest of the organization’s registers stay out of view.
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO 9001
  • Swiss nFADP
How it works

Assigned in the modules, completed in the portal.

Admins assign policies, trainings, checklists and tasks where those modules live, and each person finds their share of it in one place, with reminders doing the chasing.

01

Assign the work where it lives.

A policy or training gets an audience of named members and business roles. A process names the roles that may run it, a task an assignee, a record category can be opened for portal submission. Nothing is configured in the portal itself: it reads what the modules already know about who owes what.

The audience resolves live, so a person who joins the engineering role is enrolled in every assignment that targets it, and one who leaves drops the obligation with it.

02

Each person opens one list.

The overview leads with what is due today, tomorrow or overdue, then the open items from each work area: a policy to read and confirm, a training to complete and attest, a checklist to start or continue, a report to file, a document somebody is waiting on, an evidence request, an incident to report, or a check to fix on their own laptop.

Only what is theirs.

Visibility is the person’s own attachment to the item, checked on every read. An item that is not assigned to them reads as not found, a filed report is visible only to whoever filed it, and nobody on the portal sees the fleet, another person’s devices or the registers behind the portal.

03

Switch sections off, obligations stay.

Settings holds one switch for the whole portal and one per section. A section that is off leaves the navigation and stops answering, bookmarked links included, because the check runs in the router. The data underneath is untouched: assignments keep their due dates and reminders and remain visible in the admin app, so you switch a section off because you do not use that workflow, not to pause it.

Why it’s built this way

Built so nobody sees more than their share.

Four choices behind how the employee portal works here — each one something you can check, not an adjective.

01

Own-attachment, enforced at the query.

A person sees an item only because an active assignment or one of their business roles targets them. Anything else reads as not found rather than forbidden, so the portal never confirms what the rest of the register holds. A filed incident or report is visible to its filer and to nobody else on the portal.

02

A role that never opens the admin app.

The Employee role is portal-only: those people never see the admin app, its registers or its reports. Admins and members can use the same portal for their own items, so the surface is one, not two.

03

Composed in settings, enforced on the server.

You switch the portal on or off as a whole and each section on its own. A section that is off leaves the navigation and its pages stop answering, bookmarks included, because the switch is checked in the router, not hidden in the menu. Switching a section off changes nothing about obligations: due dates, reminders and assignments stay as they were.

04

Everything else keeps its own record.

A policy is done when the person confirms they read the approved version. A training is done when they attest to it, and the record says exactly that. A checklist saves as it goes and lands as a dated submission, a device check reports pass or fail with the fix steps, and each of those records lives in the module it belongs to, not in the portal.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where the employee portal connects.

The portal shows what the modules assign: policies to acknowledge, trainings to attest, tasks to finish, and the checks on each person’s own device.

policyv1.3
access_control {
require mfa = true
}

Policies

Read the approved version, confirm you understood it.

Security awareness · 22 min
I have completed this training14:52 / 22:00

Trainings

Work through the material, attest to the completion.

TSK-012Document backups
TSK-013Access review
TSK-014Scope statementFri

Tasks

Assigned directly or through a business role.

5 of 6 checks pass · 41 min ago

Device management

The six checks on your own laptop, with the fix steps.

FAQ

The questions evaluators ask.

Who can use the portal?

Every member of the organization. The Employee role sees only the portal and never the admin app; owners, admins, members and auditors can open the same portal for their own assignments. An external contact has no access at all and is kept on the roster only to be referenced.

What does an employee see, and what can they not see?

Only what is attached to them: policies and trainings assigned to them or to a role they hold, tasks, checklists and report forms their roles may run, documents and evidence requests aimed at them, incident reporting, and the computers they enrolled themselves. They never see the fleet, another person’s reports or any register of the ISMS, and an item that is not theirs reads as not found.

Do employees take a seat?

Yes, like every role except external contacts. An Employee counts toward the Free plan’s three team members the same way a member does, and Business has no user limit. What the role never needs is admin-app access: it opens the portal and nothing else.

Can I switch parts of the portal off?

Yes, in Settings under Employee portal: one switch for the whole portal and one per section (policies, trainings, tasks, processes, documents, evidence, incidents, devices). A switched-off section disappears from the navigation and its pages stop answering, bookmarks included. Obligations are untouched: assignments keep their due dates and reminders and stay visible in the admin app.

How do portal-only people hear about new work?

By email. Reminders go to the people who owe an item, ahead of the due date and again when it is overdue, and stop for anyone who has completed the current cycle. Portal-only employees have no in-app inbox, so the email is the whole of what reaches them, and the portal’s overview shows what is due today, tomorrow or overdue as soon as they open it.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Acknowledgements, attestations, submissions and device posture are stored in the modules they belong to and export with them. Your data and evidence are yours and exportable in full at any time, with no lock-in.

Give each person their share, not the whole ISMS.

Assign policies, trainings, checklists and tasks where they live, let each person work through their own list in the portal, and let the completions and submissions build the record in the modules that own them.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free