Administration
Configure the workspace; do not customise the code
Custom fields, import mappings, notification rules, lifecycles, locales and module switches are settings an administrator changes. Nothing on this page needs a release.
- Custom fields on any module, typed and validated, without a schema change
- Workbook import for organisation, assets, policies, findings, risks, third parties and custom controls
- Additive, merge and sync import modes with validation before commit
- Per-user and per-tenant locale, including right-to-left languages
In the application · Administer
- Settings
- Custom fields
- Data import
- Notifications
- Workflow manager
- Modules
- Guide
Draft·asset-coordinator creates
Data import
Bring what you already have
The import hub reads header-based workbooks — columns may appear in any order — validates every row, and reports what would change before anything is written. Framework content is imported the same way, into a staged release.
- Entities, locations, departments and functions in one workbook
- Assets, policies, findings, appetite definitions, risk registers and third parties
- Additive, merge, sync and clear-data modes
- Validation report per row before commit
Level 3: Well Defined
A standard process is defined and followed across the organisation.
Every question in the control library carries its own written descriptor at each level.
Configuration
Fields, notifications and languages as settings
Custom field definitions live per company and appear on the record forms, filters and exports of the module they extend. Notification rules and templates decide who is told what, on which channel. Locale is chosen per user with a tenant default.
- Custom field definitions and values per module, per company
- Notification rules, templates, recipients and per-user preferences
- Module switches per company and read-only grants per user
- In-app guide and explain-access tooling for administrators
| Action | asset-viewer | asset-coordinator | asset-approver | asset-admin |
|---|---|---|---|---|
| View | Allowed | Allowed | Allowed | Allowed |
| Create and edit | Not allowed | Allowed | Not allowed | Allowed |
| Submit for intake | Not allowed | Allowed | Not allowed | Allowed |
| Send to review | Not allowed | Allowed | Not allowed | Allowed |
| Send back | Not allowed | Allowed | Allowed | Allowed |
| Approve | Not allowed | Not allowed | Allowed | Allowed |
| Activate | Not allowed | Not allowed | Allowed | Allowed |
| Module settings | Not allowed | Not allowed | Not allowed | Allowed |
Every module ships bundles at this granularity. Segregation-of-duties conflicts are declared as rules, with logged exceptions.
Solutions by role
Built for your team
See administration in your environment
A walkthrough scoped to your entities, your frameworks, and the way your programme is actually run.