devguard

People

People is where you manage the individuals your compliance work is tracked against — their access, entitlements, and activity history.

Overview

The People section is the central place to manage everyone in your organization that compliance work is tracked against. From here you can invite members, manage their roles, deactivate or reactivate access, review their entitlements, and follow their activity and presence.

Business roles live under People → Roles, and the organization chart under People → Organization Chart.

People list

The list shows every person in a single table that unifies active members and pending invitations.

ColumnDescription
NameThe person's name (or their email for invitations that aren't accepted yet). Select it to open the detail view. A presence dot on the avatar shows whether the person is currently online.
Last activeHow long ago the person was last active (e.g. "5 minutes ago"), or Never if they've never signed in.
StatusActive for members, Inactive for deactivated members, Pending for open invitations, Expired for invitations past their expiry.
RoleThe organization role: Owner, Admin, Member, Auditor, Employee, or External.
ActionsEdit, Detail, Deactivate/Reactivate, or Delete — depending on your permissions.

The presence dot and the Last active column are only visible to owners and admins. Other members don't see them.

Roles

  • Owner — full control of the organization. Owners can't be edited, deactivated, or removed from the list.
  • Admin — can manage members, settings, and most resources.
  • Member — reads every register and takes part in comments.
  • Auditor — inspects everything in the application but changes nothing, not even a comment. Meant for the certification auditor or an internal audit function that needs to see the registers without being able to touch them. An auditor occupies a seat like a member.
  • Employee — uses the employee portal only: policies to acknowledge, trainings, tasks, and incident reports. Employees never see the application itself.
  • External — a contact with no access at all, neither to the application nor to the portal. Externals are kept on the roster so they can be referenced in compliance records, for example as members of a business role or as the subject of an access review. An external contact does not occupy a seat; changing an external contact to any other role takes a seat at that moment.

What each role can do

CapabilityOwnerAdminMemberAuditorEmployeeExternal
Sign in to the application✓✓✓✓✗✗
Use the employee portal (policies, trainings, tasks, incidents)✓✓✓✓✓✗
Read every register, report and the audit log✓✓✓✓✗✗
Comment and mention colleagues✓✓✓✗✗✗
Create, edit, archive and delete records✓✓✗✗✗✗
Map controls and set coverage assessments✓✓✗✗✗✗
Invite people, change roles, deactivate access✓✓✗✗✗✗
Organization settings, integrations, portal switches✓✓✗✗✗✗
Billing and subscription✓✓✗✗✗✗
Transfer ownership, delete the organization✓✗✗✗✗✗
Use the AI assistant and MCP server (read tools)✓✓✓✓✗✗
Use the AI assistant's write tools✓✓✗✗✗✗
Receive in-app notifications✓✓✓✓✗✗
Receive notification emails✓✓✓✓✓✗
Can be a member of a business role (owner, approver, assignee)✓✓✓✓✓✓
Occupies a seat✓✓✓✓✓✗

Read access for members and auditors is complete: anything an admin can open, they can open. What separates them is writing. A member may take part in comment threads; an auditor may only read them. Employees never see the application: the portal is their whole surface, and it shows only what is assigned to them. Externals see nothing at all, so a deep link sent to one lands on a notice explaining that.

Actions

  • Edit — opens a side sheet to change the person's role. It's built to expand with more profile fields over time.
  • Detail — opens the person's detail view.
  • Deactivate / Reactivate — suspends or restores a member's access to this organization (see Deactivating access).
  • Delete / Revoke — removes a member from the organization, or revokes a pending invitation.

Inviting people

Use Invite Member to send an invitation by email and assign a starting role. Pending invitations appear directly in the list with a Pending status until they're accepted or expire.

Showing inactive people

By default the list shows active members and open invitations. Toggle Show inactive to switch to an inactive-only view that lists the members whose access has been deactivated.

Filtering by role

Use the Role filter to narrow the list to one organization role. Owners and admins shows everyone who can manage the organization, which is the list to check before transferring ownership or when reviewing who holds administrative access.

Seat limit

When your plan limits the number of people, a banner above the list shows how many seats are used once you approach the limit. A pending invitation holds a seat until it is accepted, revoked or expires. External contacts do not occupy a seat.

Deactivating access

Deactivation suspends a person's access to the current organization without deleting them. It's an org-scoped block, not an account deletion: the user account stays intact, their data is preserved, and they keep any access they have to other organizations.

  • Owners and admins can Deactivate a member from either the people list or the person's detail view. Owners themselves can't be deactivated.
  • A deactivated person shows the Inactive status and moves out of the default view (find them via Show inactive).
  • When a deactivated person opens the application, they see a notice explaining their access was deactivated and an option to log out, instead of the usual content.
  • Reactivate restores their access immediately.

Use deactivation (rather than delete) when you want to revoke access temporarily or keep a person's history while they're offboarded.

Person detail

Selecting a person opens a dedicated detail view. The header shows the person's avatar (with a presence dot for owners and admins), an Active or Inactive badge, and — for owners and admins — when they were last active. From here owners and admins can also Deactivate or Reactivate the person.

Below the header, tabbed navigation organizes the rest:

  • Overview — the person's core details: name, email, role, status, and when they joined.
  • Entitlements — the assets this person can access, derived from their business-role memberships, with the role that grants each one. (An asset's access is defined by membership roles; a person inherits an asset's access through the roles they belong to.)
  • Access Reviews — the access-review campaigns (onboarding, offboarding, and periodic reviews) that affect this person, whether targeted at them directly or through a business role they belong to.
  • Tasks — the tasks this person is responsible for, whether assigned to them directly or through a business role they hold. The Add task button here pre-assigns the new task to this person, so you can hand off work without leaving their profile.
  • History — a searchable audit-log feed of everything this person has done in the application, grouped by day.

More tabs — such as Policies, Trainings, and Comments — will be added here as those features become available.

How is this guide?

On this page