Tiers rank the companies in a portfolio by criticality to your organization and by security risk. The Portfolio Risk Matrix in Continuous Monitoring uses tiers. In Vendor Risk Management, vendor profile tiers contain requirements for each vendor. A user's role determines who can view and modify each kind of tier. This article lists the tier permissions for each role and for each action.
Roles referenced on this page: Users with the Admin, Group Admin, Portfolio Manager, Operations, Internal Business User, User, or View Only role.
What can my role do?
Use this section to find everything a specific role can and can't do with tiers. For a breakdown by action instead, see By action below.
- Can view tiers in the Portfolio Risk Matrix.
- Can add, edit, and remove tiers, modify companies in a tier, and set risk thresholds.
- Can use the vendor profile Tiering page in Vendor Risk Management. [Confirm whether this role can view only or also modify. The current article does not say.]
- Can view tiers for their group.
- Can add, edit, and remove tiers, modify companies in a tier, and set risk thresholds for their group.
- Vendor profile tiers do not apply to this role.
- Can view tiers for their group.
- Can add, edit, and remove tiers, modify companies in a tier, and set risk thresholds for their group.
- Vendor profile tiers do not apply to this role.
- Continuous Monitoring tiers do not apply to this role.
- Can use the vendor profile Tiering page in Vendor Risk Management. [Confirm whether this role can view only or also modify. The current article does not say.]
- Continuous Monitoring tiers do not apply to this role.
- Can view vendor profile tiers.
- Cannot modify vendor profile tiers.
- Can view tiers for their group.
- Cannot add, edit, or remove tiers, modify companies in a tier, or set risk thresholds.
- Vendor profile tiers do not apply to this role.
- Continuous Monitoring tiers do not apply to this role.
- Can view vendor profile tiers.
- Cannot modify vendor profile tiers.
By action
Permissions key
✅ = Is permitted.
❌ = Not permitted.
➖ = Not applicable and not permitted.
- Access tiers in the
Portfolio Risk Matrix -
✅ Admins can do this.
✅ Group Admins, Portfolio Managers, and Users can view tiers for their own group only.
➖ Not applicable to Internal Business Users, Operations, and View Only.
- Modify tiers
-
✅ Admins can do this.
✅ Group Admins and Portfolio Managers can modify tiers for their own group only. [Conflict: the Portfolio Risk Matrix permissions article says Group Admins and Portfolio Managers cannot set risk thresholds. Confirm.]
❌ Users cannot do this.
➖ Not applicable to Internal Business Users, Operations, and View Only.
Actions include: Add, edit, and remove tiers, modify companies in a tier, and set risk thresholds.
- Manage vendor tags on the
Tiering page in VRM -
✅ Admins and Operations can use the page. [Confirm whether they can view only or also modify. The current article does not say.]
✅ Internal Business Users and View Only can view only.
➖ Not applicable to Group Admins, Portfolio Managers, and Users.
- January 3, 2025: Vendor tiering.
- November 18, 2024: Separated from User Permissions and added VRM/TMH roles.
Comments
Please sign in to leave a comment.