Collaboration permissions by role and by action

The Client/Vendor Access Program lets users invite another company to the Bitsight platform, for example to help a third party improve its Bitsight Security Rating. A user's role determines who can assign a point of contact (POC), invite companies, manage collaboration messages, set up client registration, and view progress. This article lists the collaboration permissions for each role and for each action.

Roles referenced on this page: Users with the Admin, Group Admin, Portfolio Manager, Operations, Internal Business User, User, or View Only role.

What can my role do?

Use this section to find everything a specific role can and can't do with collaboration. For a breakdown by action instead, see By action below.

What can an Admin do with collaboration?
  • Can assign a point of contact (POC) for portfolio companies and edit the POC's information.
  • Can invite a company to collaborate.
  • Can edit or delete collaboration messages.
  • Can generate a registration page for clients to sign up for the Client Access Program.
  • Can view invitations and collaboration progress.
What can a Group Admin do with collaboration?
  • Can assign and edit the POC for companies in their own group.
  • Can invite a company to collaborate.
  • Can edit or delete collaboration messages.
  • Cannot generate a registration page for clients.
  • Can view invitations and collaboration progress for their own group.
What can a Portfolio Manager do with collaboration?
  • Cannot assign a POC.
  • Can invite a company to collaborate.
  • Can edit or delete collaboration messages.
  • Cannot generate a registration page for clients.
  • Can view invitations and collaboration progress for their own group.
What can an Operations user do with collaboration?
  • Collaboration permissions do not apply to this role.
What can an Internal Business User do with collaboration?
  • Collaboration permissions do not apply to this role.
What can a User do with collaboration?
  • Cannot assign a POC.
  • Can invite a company to collaborate.
  • Can edit or delete collaboration messages.
  • Cannot generate a registration page for clients.
  • Can view invitations and collaboration progress for their own group.
What can a View Only user do with collaboration?
  • Collaboration permissions do not apply to this role.

By action

Permissions key

✅ = Is permitted.

❌ = Not permitted.

➖ = Not applicable and not permitted.

Assign a point of contact

Assign a POC for portfolio companies through the Bitsight API, and edit the POC's information.

✅ Admins can assign a POC for any company.

✅ Group Admins can assign a POC for companies in their own group only.

❌ Portfolio Managers and Users cannot do this.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Invite a company

Invite a company to collaborate. You must be subscribed to the recipient organization. For Vendor Risk Management and Trust Management Hub connections, see establish connections.

✅ Admins, Group Admins, Portfolio Managers, and Users can do this.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Manage messages

Edit or delete collaboration messages.

✅ Admins, Group Admins, Portfolio Managers, and Users can do this.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Set up client registration

Generate a registration page for clients to sign up for the Client Access Program.

✅ Only Admins can do this.

❌ Group Admins, Portfolio Managers, and Users cannot do this.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

View progress

View invitations and collaboration progress in the Continuous Monitoring app (Collaboration) or the Insurance app (Access Invitations).

✅ Admins can view invitations and progress for all companies.

✅ Group Admins, Portfolio Managers, and Users can view invitations and progress for their own group only.

➖ Not applicable to Internal Business Users, Operations, and View Only.
 

Publish Date or Recent Edits
  • November 25, 2024: Separated from User Permissions and added VRM/TMH roles.
Was this article helpful?
0 out of 1 found this helpful

Comments

0 comments

Please sign in to leave a comment.