Skip to content

Entities

An entity is a legal or administrative body: a vendor, a supplier, a client, a partner, a subsidiary, or your own organisation. It is the unit of organisational identity in third-party work — everything else in the section hangs off it. Get the register right first, because a solution with no provider and a questionnaire with no vendor are both dead ends.

Third parties → Entities in the sidebar. The list shows Reference ID, Name, Description, Domain, Parent entity, Relationship and Default criticality, with Labels, Reference link and the timestamps available as optional columns. Filters cover domain, parent entity, relationship and labels.

Name, Description and Reference ID identify the entity. Mission describes what it does. Country and Currency place it, and Legal identifiers is a free-form set of registry codes — LEI, EUID, VAT, DUNS and so on — so the same organisation can be matched against external sources. Reference link points at the vendor’s site or your internal record, and Is active retires an entity without deleting it, which keeps past assessments readable.

Parent entity attaches a subsidiary or a branch to its group, and the parent’s page lists its Branches in return. Relationship classifies the tie — supplier, client, partner, and whatever else your organisation defines — and is one of the register’s most useful filters.

Every entity lives in a Domain, which governs who can see it. Owned domains is the other direction: it records which domains this entity is responsible for, which is how an internal business unit is modelled as an entity.

Four sliders capture your standing view of the entity, and prefill new stakeholder analyses so you are not re-typing the same judgement for every solution:

RatingRangeMeaning
Dependency0 to 4How much you rely on them
Penetration0 to 4How deep into your environment they reach
Maturity1 to 4How well run their security is
Trust1 to 4How much confidence the relationship warrants

The Default criticality column is derived from them: dependency multiplied by penetration, divided by maturity multiplied by trust. Exposure over assurance. It sorts, so the top of the list is where to start.

Open an entity and the tabs carry the rest of the relationship:

  • Entity assessments — every review of this third party, past and current.
  • Representatives — the people who speak for it.
  • Solutions — the products and services it provides.
  • Contracts — the agreements covering those solutions, when the contracts module is enabled.

Create the entity first, then its representatives and solutions, then the assessment — each step references the one before it.