Skip to content

People

Everything QStack tracks about training, approvals, and escalation ultimately traces back to a person. This page covers the people model that every other module builds on: persons, job functions, workflow roles, and the manager chain.

You'll use this page as an Org Admin setting up new starters, a Quality role holder confirming coverage, or a line manager checking who reports to you.

Persons

Every user in QStack is also a person — a regulated-quality-system concept with a job function, a training record, a signing history, and an optional manager (another person, used for escalation and approvals).

A person can exist without a user account. This matters for contractors and external auditors: you can record their training and signatures without giving them a login. See Vendors & Audits for how external auditors are recorded by name without a system account.

Separately from the person concept, every user account also carries a coarse application role — Org Owner, Org Admin, User, or Reader — which controls what they can do in the application (manage billing, manage users, use the system, or just view it). Reader is view-only and doesn't consume a billable seat, so you can give inspectors, leadership, or occasional staff free read access without it costing you anything.

Add a person

  1. Click New Person and fill in name, email, job function(s), and manager.
  2. Alternatively, at onboarding or in bulk, upload a CSV of people (name, email, job function, manager), or — if your tenant uses Okta or Azure AD — let people be created automatically on first SSO login (just-in-time provisioning).
  3. Assign at least one job function. This is what drives which training requirements apply to them — see below.
  4. If the person reports to someone else in the organization, set their manager. This feeds escalation and training-plan approvals.

Note

A person doesn't need a user account to exist in QStack. If you need to record training or signatures for a contractor who won't be logging in, create the person without inviting them as a user.

Job functions

A job function is a named role in your organization — "QC Analyst", "Production Operator", "QA Reviewer". Job functions are the unit of assignment in the role-based training matrix: a person may hold multiple job functions at once, and each one can carry its own list of training requirements.

Job functions are typically defined at onboarding, either by hand or imported from a CSV, and refined afterward as your organization's structure evolves.

Workflow roles

Workflow roles are different from application roles: they're named quality responsibilities that gate signatures and decisions across the modules, rather than permission levels on a user account.

Workflow role What it gates
Quality The quality-unit authority. Approves deviation classifications and closures, document retirements, record cancellations, vendor status decisions, change approvals, and complaint closures, and signs the periodic audit-trail review.
Line manager Derived automatically from the manager relationship on each person — used for escalations and training-plan approvals.

Every tenant must designate at least one Quality role holder — QStack blocks GxP workflows until this is done. Designating two or more is recommended, so there's absence cover for a role that so much of the system depends on.

A single person can hold multiple roles at once. In a five-person company, the same person is often Org Admin, a Quality role holder, and the owner of several documents — QStack doesn't stop that. What it does enforce is described in Segregation of duties: regardless of which roles someone holds, they can't review or approve an item they authored or performed themselves.

The manager chain

Each person's optional manager relationship does two things:

  • Escalation. If someone's task goes overdue, QStack notifies them directly first, then escalates to their manager after a tenant-configurable delay (7 days by default for training assignments), and finally to Quality role holders if it's still open after that.
  • Training-plan approval. Line managers approve training plans for their direct reports.

Set the manager relationship when you add a person, and keep it current as your organization changes — escalation and approval routing both depend on it being accurate.

How job function drives training

Job function is the connective tissue between People and Training:

  1. Each job function has a list of training requirements — controlled documents, mostly, plus the occasional external course reference.
  2. The training matrix is the cross product of every job function and its requirements.
  3. When a person is added to a job function, QStack automatically creates training assignments for every requirement on that job function's list, flagged new_hire.
  4. When a requirement is added to a job function that already has people assigned to it, everyone currently holding that job function gets a new assignment, flagged matrix.
  5. If a person holds multiple job functions, their training requirements are the union of all of them.

This is why getting job function assignment right matters beyond org-chart bookkeeping — it's the mechanism that decides who gets trained on what, automatically, without anyone having to remember to assign it by hand.

Application roles vs. workflow roles

These two concepts sound similar but answer different questions, and it's worth keeping them straight:

Application role Workflow role
Answers What can this account do in the software? What quality responsibility does this person hold?
Values Org Owner, Org Admin, User, Reader Quality, Line manager
Set on The user account The person
Examples of effect Whether you can manage billing or invite users Whether you can approve a deviation classification, sign a document retirement, or receive escalations as someone's manager
Seat cost Reader is free; the others consume a billable seat No cost of its own — it's a responsibility, not an account tier

A person can combine any application role with any workflow role. In a five-person company it's common for the same individual to be an Org Admin (application role) and the sole Quality role holder (workflow role) — QStack doesn't require these to be held by different people, but it does enforce segregation of duties on individual signatures regardless of which roles someone holds. See Segregation of duties.

Your organization as a tenant

Your organization is a single tenant in QStack: it has its own users, its own data, and its own policies, and it's isolated from every other QStack customer at the database level — nothing you configure here is visible to, or affected by, any other tenant. Tenant-level settings — things like signing-strength policy, retention periods, and reminder cadences referenced throughout this help site — are configured by your Org Admin, typically during onboarding.