Skip to content

Roles

Last checked on

Roles describes the functions in your organisation, such as security officer or lead developer: what each one is responsible for, what it may decide, who holds it and which competencies it requires.

Why this protects your organisation

Who decides whether a new supplier may process customer data? Who approves access to production? If the answer is "whoever happens to be around", decisions get made twice or not at all, and nobody feels accountable when something goes wrong. Writing down responsibilities and authorities per role settles that in advance. ISO 27001 clause 5.3 asks leadership to assign these responsibilities and make them known.

Steps

  1. Open Roles in the Organisation group.
  2. Click New Role.
  3. Enter the Name of the role, then describe its Responsibilities and Authorities in plain language.
  4. Select the People who hold this role and click Create.
  5. On the role's page, add what holders of this role need to be competent at under Competency requirements.

The list shows each role's Name and how many People hold it.

The fields

  • Name What you call the role internally, such as Security officer, Lead developer or Office manager.
  • Responsibilities What this role looks after within your management system. For example: keeps the risk register up to date and reports on it every quarter.
  • Authorities What this role may decide. For example: approves access to production systems and may accept a risk up to the agreed threshold.
  • People Everyone who holds the role. One person can hold several roles, and they show up in the Roles column on People.

Competency requirements

On a role's own page you record what its holders need to know or be able to do, each with a Competency name and a Description. The column Who needs attention shows, per requirement, who holding this role is still missing it or has an expired qualification. The same information for all roles together is in the Competency overview.

Roles are also used in the task templates: a template can give its task to the first person with a given role.

If it does not work

The People list is empty

You choose holders from People. Add the person there first.

I am looking for the rights of users in Trustbird

This screen is about roles in your own organisation. Who may do what in the Trustbird workspace (owner, member or advisor) is set on the Members screen.

I can edit the role but not its competency requirements

Competency requirements fall under the Improvement module. An advisor needs edit rights for that module as well, next to Organisation.

Screens this is about

  • Roles

Read next