💡 Still using the classic Drata experience? Refer to Key Personnel Info for the original UI.
Key Personnel Information establishes who is accountable for security, compliance, and governance at your organization.
Prerequisites
Only Admins can manage Key Personnel Information.
Personnel must already exist in Drata to be assigned.
Access Key Personnel Information
Select Settings.
Go to Organization details.
Open the Key personnel tab.
What you configure here
You assign individuals responsible for core governance functions. Each role represents responsibility, not just a job title. If your organization does not have a formal title (for example, no CISO or Board), assign the person who performs the responsibilities described.
Board of Directors
If your organization has a board:
Assign the appropriate individuals
Include links to public profiles where applicable (LinkedIn is commonly used)
If you are an early-stage company, it can be acceptable for founders or executives to fulfill board-level responsibilities. Auditors typically evaluate function, not formality
Common mistakes to avoid
Leaving roles unassigned: Auditors may flag missing governance ownership.
Assigning inactive users: Ensure assigned personnel are current and active in Drata.
Using titles instead of responsibility: Auditors care about who owns the responsibility, not the title text.

