Overview
Before contributing to a maturity assessment in Hyver, it's important to understand the permission structure and who can do what. This article outlines which users can view, rate, and edit maturity-related content, and what’s required to ensure responsible input.
Who Can View What
All Hyver members can view NIST functions and maturity scores.
Viewing linked findings (associated with NIST subcategories) is limited to:
Engagement members, if sharing permissions allow
Restricted members (when this is the selected sharing mode)
Company-level administrators, if not restricted by sharing permissions
Note: Linked findings do not affect maturity score calculations.
Who Can Edit or Contribute
Only members with the right permissions can actively contribute to or change the maturity assessment:
Action | Who Can Perform It |
Rate NIST subcategories | Administrators, Power Users |
Link findings, add technology and process assets | Administrators, Power Users |
Edit NIST section in a finding | Company Admins OR Editors at the engagement level with Findings & Graph initiator permission |
Skill Requirements
Anyone responsible for rating NIST subcategories must:
Understand the NIST Cybersecurity Framework
Be familiar with how subcategories apply to their specific organization
This ensures maturity scores are realistic and meaningful — not guesswork.
Wrap-up / Next Steps
Getting permissions right helps maintain the integrity of your maturity assessment. Make sure the right people are involved, and that they’re equipped with the right knowledge to evaluate your cybersecurity posture with confidence.
