Tiers permissions by role and by action

Tiers rank the companies in a portfolio by criticality to your organization and by security risk. The Portfolio Risk Matrix in Continuous Monitoring uses tiers. In Vendor Risk Management, vendor profile tiers contain requirements for each vendor. A user's role determines who can view and modify each kind of tier. This article lists the tier permissions for each role and for each action.

Roles referenced on this page: Users with the Admin, Group Admin, Portfolio Manager, Operations, Internal Business User, User, or View Only role.

What can my role do?

Use this section to find everything a specific role can and can't do with tiers. For a breakdown by action instead, see By action below.

What can an Admin do with tiers?
  • Can view tiers in the Portfolio Risk Matrix.
  • Can add, edit, and remove tiers, modify companies in a tier, and set risk thresholds.
  • Can use the vendor profile Tiering page in Vendor Risk Management. [Confirm whether this role can view only or also modify. The current article does not say.]
What can a Group Admin do with tiers?
  • Can view tiers for their group.
  • Can add, edit, and remove tiers, modify companies in a tier, and set risk thresholds for their group.
  • Vendor profile tiers do not apply to this role.
What can a Portfolio Manager do with tiers?
  • Can view tiers for their group.
  • Can add, edit, and remove tiers, modify companies in a tier, and set risk thresholds for their group.
  • Vendor profile tiers do not apply to this role.
What can an Operations user do with tiers?
  • Continuous Monitoring tiers do not apply to this role.
  • Can use the vendor profile Tiering page in Vendor Risk Management. [Confirm whether this role can view only or also modify. The current article does not say.]
What can an Internal Business User do with tiers?
  • Continuous Monitoring tiers do not apply to this role.
  • Can view vendor profile tiers.
  • Cannot modify vendor profile tiers.
What can a User do with tiers?
  • Can view tiers for their group.
  • Cannot add, edit, or remove tiers, modify companies in a tier, or set risk thresholds.
  • Vendor profile tiers do not apply to this role.
What can a View Only user do with tiers?
  • Continuous Monitoring tiers do not apply to this role.
  • Can view vendor profile tiers.
  • Cannot modify vendor profile tiers.

By action

Permissions key

✅ = Is permitted.

❌ = Not permitted.

➖ = Not applicable and not permitted.

Access tiers in the 
Portfolio Risk Matrix

✅ Admins can do this.

✅ Group Admins, Portfolio Managers, and Users can view tiers for their own group only.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Modify tiers

✅ Admins can do this.

✅ Group Admins and Portfolio Managers can modify tiers for their own group only. [Conflict: the Portfolio Risk Matrix permissions article says Group Admins and Portfolio Managers cannot set risk thresholds. Confirm.]

❌ Users cannot do this.

➖ Not applicable to Internal Business Users, Operations, and View Only.

Actions include: Add, edit, and remove tiers, modify companies in a tier, and set risk thresholds.
 

Manage vendor tags on the 
Tiering page in VRM

✅ Admins and Operations can use the page. [Confirm whether they can view only or also modify. The current article does not say.]

✅ Internal Business Users and View Only can view only.

➖ Not applicable to Group Admins, Portfolio Managers, and Users.
 

Publish Date or Recent Edits
  • January 3, 2025: Vendor tiering.
  • November 18, 2024: Separated from User Permissions and added VRM/TMH roles.
Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.