People

Everyone on one roster,
each with the right role.

People is the registry of everyone your compliance work is tracked against, from the owner to the external data protection officer who never signs in. Six roles decide who reads, who writes and who only sees the portal, deactivation keeps a leaver’s history intact, and the organization chart stays linked to the same names.

Start for freeBook a conversation
++++
app.devguard.ch / people / chart
Roster · 25 people
Roster
25
people · 18 take a seat
Owners & admins04
Members09
Auditor01
Employees04
External07
2 invitations pending
Organization chart
editing
AK
A. Klein
CEO
MR
M. Rossi
CISO
TS
T. Schmid
CTO
DP
D. Peter
DPOExternal
JL
J. Lee
Job title missing
AddAuto-formatExport PDF
Cards stay linked to the roster: a leaver drops off the chart, a deactivated member dims until reactivated.
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO 9001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO 9001
  • Swiss nFADP
How it works

Invited, assigned, and drawn on the chart.

One roster feeds everything that names a person: roles, business-role memberships, entitlements, access reviews, tasks and the organization chart.

01

Invite people and give each a role.

Invite someone by email with a starting role and they appear in the list as pending until they accept. The list unifies active members and open invitations, with each person’s status, organization role and last activity in one table. Owners and admins also see a presence dot showing who is online right now.

The role decides the surface: owners and admins run the organization, members read every register and comment, auditors read everything and write nothing, and employees see only the portal.

Externals without a seat.

An external contact has no access to the application or the portal, but stays on the roster so you can reference them where compliance records need a name: as a member of a business role, or as the subject of an access review. An external takes no seat until you change their role.

02

Follow what each person holds.

A person’s detail view shows the assets they can access, derived from the business roles they belong to, with the granting role next to each one, and every access review that affects them, whether onboarding, offboarding or a periodic campaign, targeted at them directly or through a role.

The tasks tab lists what they are responsible for, directly or through a role, with an add button that pre-assigns the new task to them. The history tab is a searchable feed of everything the person did in the application, grouped by day.

03

Draw the organization chart auditors ask for.

The organization chart is an interactive canvas everyone can view and owners and admins can edit. Place members from the roster, add external persons who are not in the app, group them into teams, give each card a job title and drag reporting lines between them. A card without a job title is flagged, because an unnamed role is a gap in the picture the chart is meant to give.

Auto-format lays the chart out along its reporting lines, the dashboard shows it as a card, and Reports exports it as a PDF. Because the cards are linked to People, a leaver’s card disappears and a deactivated person’s card dims without anyone redrawing anything.

Why it’s built this way

Built around who may do what.

Four choices behind how the people roster works here — each one something you can check, not an adjective.

01

Deactivate, don’t delete.

Deactivation blocks a person’s access to this organization and nothing more. The account stays, their history stays, and they keep whatever access they hold elsewhere. A deactivated person who opens the app sees a notice instead of the registers, and reactivation restores everything at once. So offboarding never means deleting the trail an auditor will ask about.

02

An auditor seat that changes nothing.

The auditor role reads every register, every report and the audit log, and cannot change a thing, not even a comment. It exists for the certification auditor or an internal audit function that needs to see the workspace without being able to touch it. An auditor occupies a seat like a member, and the separation is in what they can write, not in what they can read.

03

The portal is the employee’s whole surface.

A person with the employee role never sees the application. The employee portal shows them only what is assigned: policies to acknowledge, trainings to complete, tasks, and the incident report form. Members and admins can use the portal too, but for an employee it is the entire product.

04

One roster behind every assignment.

Business roles hold the responsibility, as owner, approver or assignee, and any person on the roster can belong to one, external contacts included. Entitlements are derived from those memberships rather than typed in twice, and the organization chart stays linked to the same names: a leaver’s card disappears, a deactivated person’s card dims.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Your data and evidence are yours and exportable in full at any time, with no lock-in.

See the full feature comparison

One module of the platform

Where people connect.

A person holds business roles, inherits entitlements through them, owes tasks and trainings, and sits on the organization chart.

1,284
assets tracked
+12 today

Assets

The access an entitlement grants, asset by asset.

TSK-012Document backups
TSK-013Access review
TSK-014Scope statementFri

Tasks

Assigned to a person or to one of their business roles.

Security awareness · 22 min
I have completed this training14:52 / 22:00

Trainings

Assigned by role, so the audience follows the roster.

86%
Shared with
JDAKMR+3

Reports

The organization chart as a PDF for the auditor.

FAQ

The questions evaluators ask.

Which roles are there, and what separates them?

Six: owner, admin, member, auditor, employee and external. Owners and admins run the organization, members read every register and take part in comments, auditors read everything and change nothing, employees see only the portal, and externals see nothing at all. Read access for members and auditors is the same as an admin’s; what separates the roles is what each may write.

What happens when someone leaves?

Deactivate them. Access to this organization is blocked at once, they see a notice if they open the app, and their account, history and business-role memberships stay intact for the record. Reactivation reverses it in one step. If you remove a person instead, their card and its reporting lines leave the organization chart automatically.

Can I keep people on the roster who never sign in?

Yes, as external contacts. An external has no access to the application or the portal, but stays on the roster so you can name them in a business role, for example as an external data protection officer, or make them the subject of an access review. An external takes no seat; changing them to any other role takes one at that moment.

How do entitlements and access reviews show up per person?

A person’s detail view lists the assets they can access, derived from the business roles they belong to, with the role that grants each one next to it. The access reviews tab shows every onboarding, offboarding and periodic campaign that affects them, whether it targets them directly or a role they hold, and the history tab is a searchable feed of everything they did, grouped by day.

Do I have to maintain the organization chart separately?

No. The chart is an interactive canvas that draws on the People roster: place members, add external persons who are not in the app, group them, give each a job title and draw the reporting lines. A missing job title is flagged, cards follow the roster when people leave or are deactivated, and the chart exports as a PDF from Reports whenever an auditor asks for a current one.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. The roster, each person’s history and the organization chart are yours, the chart exports as a PDF from Reports, and your data is exportable in full at any time, with no lock-in.

One roster for everyone, the roles decide the rest.

Invite people once, give each a role, and let entitlements, access reviews, tasks and the organization chart follow the same names.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free