Short answer: Your organisation's designated admin — not Tibo Energy support. This is by design, and it aligns with how access control works under ISO 27001.
FAQ
Why does my organisation's admin control access, and not Tibo Energy?
Tibo Energy does not have visibility into your organisation's internal structure — we don't know who should or shouldn't have access to your environment. That context lives within your organisation, with the people responsible for managing it.
Under ISO 27001, access must be granted by someone with the authority and context to make that decision. Your designated internal admin is that person. Granting access without their sign-off would go against the access control principles we are certified to uphold.
Who should I contact instead?
Contact your organisation's internal Tibo EMS admin. They can grant access, assign roles, and resolve most issues directly.
If you're not sure who that is you can ask internally or check with Tibo Support.
What can Tibo Energy support actually help with?
We can look into the technical side of things:
Confirm whether your user account exists in the system
Check whether the correct roles are assigned to your account
Identify any configuration issues on our end
What we can't do is override your organisation's access decisions or determine whether you're authorised to access a given environment.
Why is this set up this way?
ISO 27001 requires that access control is enforced based on a need-to-know and least-privilege principle. Centralising that control within your organisation — rather than with Tibo Energy — ensures accountability stays where the relevant context is: inside your organisation.
It also means your organisation retains full control over who can see your data and systems, which is better for your security posture too.
