Start here

Roles and permissions

Purpose

This page explains the app’s roles and what each role can see and do: the role register in the hub, the Jira and Confluence permissions derived from it, the RACI roles on individual issues, and the confidentiality level.

The role register (hub → Roles & responsibilities)

The Roles & responsibilities page is visible to everyone; only Jira administrators can change it (hint for everyone else: “Only Jira administrators can change the roles — this page shows you who is responsible for what.”). Each role has Holders and Deputies; the + Add myself button speeds up the start, and changes are stored via Save all changes.

RoleRequired?Special
Top managementRequired
Information security officer (CISO)Required (one person)Must be named before installation (Language, project type and required entries)
ISMS teamOptionalThe only role that can also hold groups
Data protection officer (DPO)Optional
Internal auditOptional
Continuity/BCM officerOptional

In addition there is the card Scope: user groups — the groups the ISMS applies to; they receive read access to the document space. On deputies, the app says: “Deputies are always notified along with the role holders on escalations — absence can never swallow an escalation.”

Roles & responsibilities: role cards with holders, deputies and groups per role, saved via “Save all changes”.

What is derived from the register

On saving (and during installation) the app grants permissions — always additive, never revoking:

Register roleJira project role in “ISMS Home”Confluence space “ISMS Home”
CISO (incl. deputies)Bearbeiter and AdministratorsRead, create pages, administer space
ISMS team (incl. deputies and groups)BearbeiterRead, create pages
Top management, DPO, internal audit, BCM (incl. deputies)BeobachterRead (top-management holders only)
Scope groupsBeobachterRead

After saving, the card Space permissions (Confluence) shows the result per person (“Permissions applied” / “already present”). If the automatic grant fails, the app shows instructions for granting them manually in the space settings. The Jira permissions can be re-applied at any time from Setup (Assigning roles and go-live checklist).

Who sees what in the hub

FunctionAll usersJira administrators only
Dashboard, Explorer, work areas, Reports (view), Automations (view), Roles & responsibilities (view), Document control
Generate reports (“Only Jira administrators can generate reports.”), toggle/run automations, change roles, save onboarding
Notifications, Setup & Configuration (nav entries hidden for everyone else)

The dashboard views follow the register: the CISO and ISMS team see all three tabs (My view, ISMS team, Top management), top management sees its tab plus My view, everyone else only My view. Important: this is tailoring, not protection — all numbers are loaded with the viewer’s own Jira permissions; anyone who may not see a project or issue will not see it on the dashboard either.

Dashboard for employees without a register role: instead of the three tabs only “My tasks” with the person's own issues and the link to document control.

RACI roles on the individual issue

Responsibilities on an issue are RACI-based: Responsible is the assignee (Jira “Assignee” field); Accountable, Consulted and Informed are the app fields 👤 Accountable (one person), 👤 Consulted and 👤 Informed (multiple people) — the field names are identical in both languages. These roles drive the e-mail notifications (Setting up notifications (RACI)) and the visibility of confidential issues (below).

Confidential issues (level “Confidential”)

Any issue in the ISMS project can be set to the Confidential level via Jira’s native Security level field (padlock icon). It is then visible only to:

  • the RACI parties named on the issue (👤 Accountable, 👤 Consulted, 👤 Informed) and the assignee,
  • the project lead and the Administrators project role,
  • the app itself (so automations and reports keep working).

Roles in document control

Document control has its own tiers, independent of the role register: setting up control and steering rounds is for page owners and space administrators; deciding (approve, reject, confirm reading) is only for the assigned person; status and counters are visible to anyone who may read the page; the named per-person state is visible to owners and space admins only. Details: Using document control.

Screenshots from the development environment with sample data.

Documentation baseline: app version 1.1.15 · 2026-08-20