Mandates
A mandate is the organization a consultancy or vCISO uses to run compliance for its clients, each client in its own isolated organization.
Overview
A mandate manages client organizations. It holds no register of its own: no frameworks, policies, risks or assets. Each client keeps its own register in its own organization, and the mandate gives you one place to look across all of them.
When the mandate is the selected organization, the sidebar shows the Mandates section and your People. Pages that belong to a register are not available there. To work inside a client, open it from Clients.
Clients
The client list shows every organization under the mandate, the clients that need attention first. For each client you see its frameworks, its coverage, its overdue tasks and the tasks due soon.
The figures are cached for a few minutes. Refresh recalculates them.
Owners and admins of the mandate can create a client and detach one from the mandate. Detaching asks whether the client keeps its data for its own people or is closed.
Members
Everyone in the mandate works in every client, in the role they hold in the mandate:
| Role in the mandate | Role in each client |
|---|---|
| Owner | Owner |
| Admin | Admin |
| Member | Member |
| Auditor | Auditor |
| Employee, external contact | No access |
You manage these people in People, like in any organization. Inviting someone, changing their role, deactivating them or removing them takes effect in every client. Someone who already belongs to a client keeps the higher of their own role there and their mandate role.
A client cannot remove or change the people the mandate brings. Detaching the client is what ends their access.
Work queue
The work queue lists the open tasks of every client, grouped by client and ordered by the most urgent task. Clients with nothing open are listed too, collapsed. Opening a task switches to that client.
The list shows the most urgent tasks across all clients. A client whose tasks are further down still shows its open and overdue counts.
Report
The portfolio report is a PDF for a quarterly review. It carries the mandate's branding on the cover and contains:
- an executive summary across all clients
- an overview of every client with coverage, open work, the next audit and the last activity
- the clients with overdue work
- the upcoming audits
The figures are recalculated when the report is generated.
Templates
Templates copies one client's setup into another. Choose a client, download its template as a JSON file, then choose the client to receive it and import that file.
The file carries the setup, not the operation: reference data, business roles, policies, risks, treatment actions, assets, vendors, evidence requirements, record categories, processes, trainings, questionnaires, frameworks and the coverage links between them.
Four things to expect from an import:
- Anything that already exists in the receiving client is kept, never overwritten, so importing the same file twice adds nothing the second time.
- Members are not copied, and business roles arrive without their people.
- Policies arrive as drafts, without their approval history.
- Files, images, comments, reviews, assessments and history are not included.
Branding, billing and support
These pages are for owners and admins of the mandate.
- Branding: your logo and colours replace devguard's for every client of the mandate.
- Billing: the licences the mandate holds. Each client uses one licence, and a demo client uses none.
- Support: the support address and help link your clients see in place of devguard's.
How is this guide?