Overview
Paramify is intentionally designed to involve as many individuals within your organization as possible in your security program, embracing the concept of "many hands make like work." This approach recognizes that GRC professionals often have a broad understanding of security across the company but may not be experts in every aspect or the specifics of implementation. Therefore, it's highly beneficial to engage domain experts and delegate specific portions of security content to them. This shared approach fosters widespread adoption throughout the organization.
Users
Users are accounts that identify which people can login to Paramify and what permissions they have (see User Types below for more details). In addition to an email address there are multiple properties that can be set per User, including name, title, department, Teams, Roles, and description.
Teams
Teams allow naming and grouping a set of Users and associating them to Roles. With many Users this can be a more convenient way to manage Role assignments than individually on each User.
Managing Users and Teams
Using the settings icon in the top-right corner, navigate to "Users & Teams". This is where you can create, edit, and delete Users and Teams within your Paramify workspace.
To create User accounts you would click "+ User". Invite each user with their work email. Once a user has been added, click on the user and assign them to specific Roles and Teams, if any.
Use the "Manage Users" button to get a table view of all Users and their assigned User Type, last activity, and to suspend or delete them.
NOTE
User authentication within Paramify is managed by your third-party SSO providers. Paramify does not create, store, or use passwords.
To create a Team click "+ Team" and then set a name and the list of members. If you click on a Team you can also assign Roles that will be inherited by members.
User Types
| Permission | Collaborator | Editor | Admin |
|---|---|---|---|
| View/Edit Elements | ✅ * | ✅ | ✅ |
| View/Edit Risk Solutions | ✅ * | ✅ | ✅ |
| Create/Edit/Delete Elements | ✅ | ✅ | |
| Create/Edit/Delete Risk Solutions | ✅ | ✅ | |
| Create/Edit/Delete Projects | ✅ | ✅ | |
| Data Import and Export | ✅ | ||
| Manage Users and access | ✅ | ||
| Manage Workspace Settings | ✅ | ||
| Early Access Features (Opt-In) | ✅ |
* More specific access allowed to Collaborators can be customized by an Admin in Workspace Settings under Collaborator Access.
Collaborator
Collaborators do not have access to individual certification projects nor the ability to view or download deliverables. Collaborators are typically users who possess valuable insights to the implementation and status of Risk Solutions in their areas of expertise like a security engineer or an HR Admin.
In Workspace Settings under Collaborator Access, an Admin can set permissions for the Collaborator User Type to have "Full Access" or "Full Access to Owned" to Risk Solutions and/or Elements.
"Full Access" allows Collaborators to view and edit all Risk Solutions and Elements. Collaborator access can be restricted to specific Risk Solutions and/or Elements by selecting "Full Access to Owned".
"Full Access to Owned" means users only have view and edit access to Risk Solutions and Elements that match the following criteria:
- The user is assigned as the reviewer or owner on the Risk Solution or Element
- The responsible role for the Risk Solution or Element is included in "Additional Roles" on the user's page under Users & Teams > Users
- The responsible role for the Risk Solution or Element is included in "Roles" on one of the user's team pages under Users & Teams > Teams
- The user's team is assigned to the Stack mapped to the Risk Solution or Element
Editor
Editors are typically internal members of the company, and enjoy full access to projects and deliverables.
Editors can create, view, edit, and delete Risk Solutions, Elements, and Projects.
Admin
Admins have no restrictions in their workspace. They can manage workspace settings and user access, and they can use data import features.
Admins can create, view, edit, and delete Risk Solutions, Elements, and Projects.
NOTE
All activities completed in Paramify by users are tracked and displayed for transparency and accountability.
Comments
0 comments
Please sign in to leave a comment.