Blog/Deputy Matrix for Key Personnel: Secure Knowledge and Approvals Before Absence

Deputy Matrix for Key Personnel: Secure Knowledge and Approvals Before Absence

3 October 2026 · ConformBase Redaktion

vertretungsmatrixschluesselpersonalnotfallplanungkrisenvorsorgebusiness-continuityvertretungfreigaben
AI-generated

A deputy is more than a name on an organisation chart

When a key person is unexpectedly absent, operational capability is determined not by the organisation chart but by whether someone has the information, access, and clearly bounded authority to decide. A deputy matrix makes those conditions visible. It connects the role, critical tasks, deputy, approval limits, and evidence in one working view. This is especially useful for business defence preparedness because staffing gaps, disruptions, and parallel decisions rarely occur one after another. The matrix helps teams settle in advance what is often unclear under time pressure: who may act, who must be informed, and what must never proceed without a second review.

The purpose is not to duplicate every activity. Good deputy coverage focuses on the few tasks where delay, a wrong decision, or missing evidence would have tangible consequences. Examples include payment approvals, customer communication during a disruption, access protection, contract decisions, reporting paths, or approval of safety-relevant work. A dependable matrix therefore separates routine work from critical handoffs. It also reveals where one person alone holds the knowledge or permission and thus becomes a bottleneck even if a formal deputy has been named.

Start with critical outcomes, not job titles

The first step is to ask which outcomes must still be delivered reliably during an absence. Write them not as a generic job description but as specific outcomes with a deadline and recipient. Examples are approving an invoice above a defined threshold, escalating a disruption to a provider, confirming the duty roster, or publishing a customer status. The existing workforce emergency plan for a crisis provides a useful starting question: what minimum staffing does the organisation need so that its most important services and protective measures continue? The matrix translates that answer into individual, transferable activities.

Assess every activity by asking how long it may remain unprocessed, what wrong decision is plausible, and what information must be checked before action. A four-hour interruption in a customer notice may need different treatment from a weekly stock report. This assessment keeps the matrix from becoming a long list of low-value deputies. It also creates clear priorities for training, access management, and exercises. The relevant business area, IT, HR, and where appropriate compliance should confirm the classification together rather than leaving it to one manager alone.

A role can carry several critical outcomes, and an outcome may require a second reviewer. The smallest useful unit is therefore not the person but the task together with its decision. For each line, add a trigger, time frame, required records, and a return rule: who documents the decision and when does responsibility return to the primary role? This precision also protects minimum staffing. It shows which combination of people can actually operate, rather than merely counting how many names are present in a shift.

Build the matrix so it is used in daily work

A practical row contains at least six fields: primary role, critical outcome, first and second deputy, decision scope, knowledge or system prerequisite, and evidence of the handover. Add a traffic light for current readiness. Green means the person has recently practised the activity and has access. Amber means a prerequisite will soon expire or can only be met with guidance. Red means there is no effective deputy. The value of the traffic light lies in its consequence: red is not a note for later but a trigger for a specific action.

The matrix belongs in the normal management rhythm. Review it when roles change, providers are added, systems change, leave is planned, and after every disruption where a handoff did not work. This links staffing planning with risk management. The business defence preparedness page can serve as a shared frame: not every risk can be eliminated, but responsibilities, information paths, and replacement capacity can be organised in advance. An organisation that updates a spreadsheet only once a year often discovers outdated access and vanished practical knowledge at the worst possible moment.

Team discussing tasks and deputies at a work tableAI-generated
A deputy matrix connects tasks, authority, knowledge, and evidence.

A useful test of clarity is this: can a suitably qualified deputy see within five minutes what to do now, which limit applies, and where the current template is held? If not, triggers are probably unclear or the matrix relies on tacit knowledge. Do not link every document directly in the table. Instead, define a stable repository, a version rule, and an owner. This keeps the matrix readable while allowing the underlying records to be updated in a controlled way.

Secure knowledge, access, and authority separately

A named deputy often fails not because of low motivation but because a prerequisite is missing. The person knows the process but lacks system permission. Or the person can open the account but does not know the contractual limit. Split every critical task into three checks: does the deputy understand the process? Can the person access the information and systems? May the person make the decision within a clear boundary? A matrix row is dependable only when all three questions are answered with evidence.

Financial, legal, or safety-related approvals are particularly sensitive. A deputy matrix must never define a protective control away. Instead, it must make visible when a second approval, four-eyes review, or escalation remains required. The article on the Labour Security Act at work shows why responsibilities and reporting paths cannot end with a generic alarm number. Apply the same principle to the internal matrix: every exception needs a named contact point, a communication channel, and a documented closure.

Access should not be requested on the day of a disruption. Check identities, rights, multi-person approvals, emergency contacts, and the route for temporary expansion of a permission in advance. This does not mean giving every deputy maximum rights. Tiered permissions and pre-agreed release steps are more sensible. Record who may test those steps and how a test is distinguished from a real transaction. This makes the matrix an instrument for controlled capability rather than a collection of broad individual powers.

Communication also needs deputy cover. A decision is only effectively handed over when the affected teams know who is currently speaking, which information is reliable, and where status is recorded. For every key role, define a short contact sequence: first deputy, specialist question, approval point, external contact. The article on reporting paths for HR offers a useful pattern. It reduces the risk that several people answer the same request in parallel or that important feedback remains in private inboxes.

Test with realistic scenarios, not reading acknowledgements

A matrix becomes credible only when it works under a realistic constraint. Choose a scenario where the primary role cannot be reached, an important system is only partially available, and a decision is needed within a fixed period. Have the deputy run the process from trigger through documentation. Observe not only the technical answer but also the search for templates, access, requests for clarification, and communication with other teams. Every exercise should produce a specific change to the matrix, work instruction, or training plan.

Vary the scenarios. Planned leave tests different weaknesses from sudden staff absence. Simultaneous absence of two people shows whether the second deputy actually works. A provider outage reveals whether contact paths and contract records are available. Use a fixed assessment sheet with time to takeover, missing information, exceeded approval boundaries, and open decisions. This turns the exercise from a performance test of individuals into a test of the system that should support them.

Person documenting tasks and decisions in a planAI-generated
Short exercises show whether knowledge, access, and authority truly fit together.

Plan the return path as well. Once the primary role is available again, it needs a compact status overview: what was decided, which deadlines are running, what exception applies, and which person is awaiting feedback? Without this handover, duplicated work or contradictory commitments can easily arise. A standard handover record with time, decision basis, and open points is often enough. The matrix only needs to point to this record and state who confirms its completeness.

Governance, maintenance, and a dependable 30-day start

Name a business owner and a process owner for the matrix. The business owner confirms content and risks for each area. The process owner manages the format, review dates, evidence logic, and escalation of red fields. HR supports role changes and competence, IT supports access, and managers support priorities. This prevents deputy coverage from being treated as private preparation by individual teams and makes it a controllable part of operational capability. The workforce-risks page for business defence preparedness can help bring that shared understanding into leadership discussions. See also: workforce risks in business defence preparedness.

A sensible 30-day start is small and testable. First select five key roles and two critical outcomes for each. Name deputies, capture the three prerequisites of knowledge, access, and authority, test one case, and close every red gap with an owner and date. In week three, test the second deputy and return of responsibility. In week four, leadership reviews only the open risks and required resources. The matrix can then grow along real changes rather than disappearing as a one-off project in a folder.

The official BSI IT-Grundschutz information is a useful reference for structuring emergency management and continuous improvement. This article is an organisational aid, not legal advice. The specific deputy arrangement must fit the organisation's tasks, contracts, permissions, employee representation, and applicable requirements. What matters is not the number of rows in the table but whether a suitable person can act in time, transparently, and within their authority when it matters.

ConformBase

Turn knowledge into training that works.

Bring compliance, privacy and security awareness into a format your people want to complete, with certificates and audit-ready evidence.

Start free trialAsk about custom courses →

← All posts

Ready for training that actually lands?

Try the combination for free: automated administration for you, learning formats that fit your team, with no minimum or credit card.

Start 14-day free trial