Skip to main content

Who Controls Access to Your EMS Environment?

Explains why access to your Tibo EMS environment is managed by your organisation's internal admin rather than Tibo Energy support.

Written by Jeroen Pleunis

Short answer: Your organisation's designated admin — not Tibo Energy support. This is by design, and it aligns with how access control works under ISO 27001.


FAQ

Why does my organisation's admin control access, and not Tibo Energy?

Tibo Energy does not have visibility into your organisation's internal structure — we don't know who should or shouldn't have access to your environment. That context lives within your organisation, with the people responsible for managing it.

Under ISO 27001, access must be granted by someone with the authority and context to make that decision. Your designated internal admin is that person. Granting access without their sign-off would go against the access control principles we are certified to uphold.


Who should I contact instead?

Contact your organisation's internal Tibo EMS admin. They can grant access, assign roles, and resolve most issues directly.

If you're not sure who that is you can ask internally or check with Tibo Support.


What can Tibo Energy support actually help with?

We can look into the technical side of things:

  • Confirm whether your user account exists in the system

  • Check whether the correct roles are assigned to your account

  • Identify any configuration issues on our end

What we can't do is override your organisation's access decisions or determine whether you're authorised to access a given environment.


Why is this set up this way?

ISO 27001 requires that access control is enforced based on a need-to-know and least-privilege principle. Centralising that control within your organisation — rather than with Tibo Energy — ensures accountability stays where the relevant context is: inside your organisation.

It also means your organisation retains full control over who can see your data and systems, which is better for your security posture too.

Did this answer your question?