Skip to content

Members and advisers

Last checked on

On Members you see who has access to this workspace and in which role: owner, member or advisor. An owner adds people, changes their role and decides which parts an external advisor may edit.

Why this protects your organisation

Not everyone who works in your management system needs the same rights. A consultant helping you towards certification should be able to read along and comment, but should not decide who else gets in or see your invoices. Giving each person a clear role limits the damage a mistake or a compromised account can do, and makes it easy to show an auditor who can change what (ISO 27001 control 5.15 on access control asks you to think this through).

Steps

  1. Open Members in the Workspace group.
  2. Check the list: each person is shown with their email address, role and edit access.
  3. To add someone, use the create button at the top of the list, choose the person under User and pick a Role.
  4. For an advisor, tick under Edit access the parts they may change. Leave it empty for read and comment only.
  5. To change a role or remove someone, open the menu at the end of their row and choose edit or delete.

Every person in a workspace has exactly one role. What they can do follows from that role, on every screen.

The three roles

  • Owner: manages the workspace itself. Only an owner adds and removes people, handles billing, changes the address of the workspace, imports from Vanta and exports the data.
  • Member: works in the management system day to day, without those management tasks.
  • Advisor: a guest, for example an implementation partner or consultant. An advisor can always read and comment. Edit rights are switched on per part: People, Policies and documents, Standards and certification, Organisation, Improvement, and Risks and controls. An advisor never invites others, never sees billing and cannot remove the workspace.

Reading the list

The Edit access column shows which parts an advisor may change. It says Read only when none are ticked. For owners and members this column stays empty, because their role already decides what they can do.

Someone who belongs to more than one workspace can have a different role in each. They move between them with Switch workspace.

If it does not work

I cannot add, change or remove anyone

Only an owner of the workspace can do that. Members and advisors can see the list but not change it.

The person I want to add is not in the User list

The list only contains people who already have a Trustbird account. Someone without an account cannot be chosen yet.

I cannot remove an owner

A workspace always keeps at least one owner. Make someone else owner first, then remove or change the other one.

The Edit access field does not appear

It only shows when the role is Advisor. Owners and members can already edit everything their role allows.

Screens this is about

  • Members

Read next