Entities
An entity is a legal or administrative body: a vendor, a supplier, a client, a partner, a subsidiary, or your own organisation. It is the unit of organisational identity in third-party work — everything else in the section hangs off it. Get the register right first, because a solution with no provider and a questionnaire with no vendor are both dead ends.
Where to find it
Section titled “Where to find it”Third parties → Entities in the sidebar. The list shows Reference ID, Name, Description, Domain, Parent entity, Relationship and Default criticality, with Labels, Reference link and the timestamps available as optional columns. Filters cover domain, parent entity, relationship and labels.
What an entity holds
Section titled “What an entity holds”Identity
Section titled “Identity”Name, Description and Reference ID identify the entity. Mission describes what it does. Country and Currency place it, and Legal identifiers is a free-form set of registry codes — LEI, EUID, VAT, DUNS and so on — so the same organisation can be matched against external sources. Reference link points at the vendor’s site or your internal record, and Is active retires an entity without deleting it, which keeps past assessments readable.
Hierarchy and relationship
Section titled “Hierarchy and relationship”Parent entity attaches a subsidiary or a branch to its group, and the parent’s page lists its Branches in return. Relationship classifies the tie — supplier, client, partner, and whatever else your organisation defines — and is one of the register’s most useful filters.
Domains
Section titled “Domains”Every entity lives in a Domain, which governs who can see it. Owned domains is the other direction: it records which domains this entity is responsible for, which is how an internal business unit is modelled as an entity.
Default ratings
Section titled “Default ratings”Four sliders capture your standing view of the entity, and prefill new stakeholder analyses so you are not re-typing the same judgement for every solution:
| Rating | Range | Meaning |
|---|---|---|
| Dependency | 0 to 4 | How much you rely on them |
| Penetration | 0 to 4 | How deep into your environment they reach |
| Maturity | 1 to 4 | How well run their security is |
| Trust | 1 to 4 | How much confidence the relationship warrants |
The Default criticality column is derived from them: dependency multiplied by penetration, divided by maturity multiplied by trust. Exposure over assurance. It sorts, so the top of the list is where to start.
Working with an entity
Section titled “Working with an entity”Open an entity and the tabs carry the rest of the relationship:
- Entity assessments — every review of this third party, past and current.
- Representatives — the people who speak for it.
- Solutions — the products and services it provides.
- Contracts — the agreements covering those solutions, when the contracts module is enabled.
Create the entity first, then its representatives and solutions, then the assessment — each step references the one before it.
Related
Section titled “Related”- Representatives — the contacts on the entity side.
- Solutions — what the entity provides you.
- Entity assessments — reviewing the relationship.
- Domains — how visibility is scoped.
