People
Last checked on
People lists everyone who works for your organisation, with their employment type and status. From here you also record their trainings and certificates and start the tasks for a colleague who joins or leaves.
Why this protects your organisation
Many security problems in small software companies start with an account that should not have existed: a former contractor who can still log in, or a new developer who never set up multi-factor authentication. Knowing who works for you, and in what capacity, is the start of every access decision and every onboarding and offboarding check. ISO 27001 asks for this in the people controls of Annex A (section 6), such as the steps before, during and after employment.
Steps
- Open People in the Organisation group.
- Click New person at the top right and fill in first name, last name, email, employment type and employment status. All five are required.
- Save the person. They now appear in the list with their status.
- When someone joins, open the menu at the end of their row and choose Colleague starts. Confirm with Create tasks.
- When someone leaves, choose Colleague leaves in the same menu, and update their employment status.
- Open a person to add trainings and certificates under Qualifications.
The list shows each person's Name with their email address underneath, their Teams, their Roles and their Status. You can search on name and email.
Employment type and status
The employment type says how someone works for you: Employee, Contractor, Freelancer, Advisor or Intern. The status follows the person through time: Starting, Active, Leaving and Left. Keep the status current, because it is the simplest way to see who should still have access.
On a person's own page
- Qualifications Trainings and certificates, each with a Type, a Title, the date it was Obtained on, an optional Valid until date and a file as Evidence. If it covers a competency that one of their roles requires, pick it under Satisfies competency. The Competency overview uses this link.
- Document acknowledgements Which established documents this person has been asked to read, and whether they have confirmed them. Confirming happens on their own documents to read page, not here.
- Tasks The tasks linked to this person, including those created by Colleague starts or Colleague leaves.
Starting and leaving
Colleague starts and Colleague leaves create a fixed set of tasks from the task templates, each with an owner, a deadline and the reason it matters. Think of creating an account and turning on multi-factor authentication for a starter, and revoking access and collecting the laptop for a leaver.
If it does not work
I do not see the button to add a person
Only owners and members can add or delete people. An advisor with edit rights for the People module can change existing people, but not add or remove them.
Colleague starts created no tasks
Trustbird does not create a task twice while the same task is still open for this person, and a template that is switched off creates nothing. The workspace owner can check this under Task templates.
The Teams and Roles columns are empty
You link people to teams on the Teams screen and to roles on the Roles screen. The columns here show the result.
Uploading evidence for a qualification fails
The file may be at most 12 MB. Adding qualifications also requires edit rights for the Improvement module if you are an advisor.
Screens this is about
- People