Getting Started
This guide walks you through your first login and helps you understand the platform’s main areas. By the end, you’ll know how to navigate the interface and where to find key features.
Signing In
Section titled “Signing In”How you sign in depends on how your deployment is configured — see Authentication for the full picture.
- Default self-hosted install (API key): navigate to your platform URL — the app authenticates with the deployment’s configured API key and takes you straight to the Control Library. Nothing to click.
- OIDC single sign-on: the Sign in button redirects you to your organization’s identity provider (the bundled Keycloak or your own IdP) — see Identity Provider.
- Google Sign-In (when enabled): click Sign in with Google and select your account (use your work account if applicable).
Understanding the Interface
Section titled “Understanding the Interface”The platform has three main areas:
Sidebar Navigation
Section titled “Sidebar Navigation”The collapsible sidebar on the left provides access to all platform sections. Hover over it to expand and see labels. Sections are grouped by function:
Overview
| Section | Purpose |
|---|---|
| Dashboard | Overview of your compliance posture |
| Analytics | Capability Posture — security implementation by KSI theme |
Controls & Frameworks
| Section | Purpose |
|---|---|
| Control Library | Browse all 1,451 SCF controls |
| Framework Mappings | View framework-to-control mapping matrix |
| Control Scoping | Scope controls and identify framework coverage gaps |
Risk & Third Party
| Section | Purpose |
|---|---|
| Risk Register | 5x5 risk matrix and risk assessments |
| Vendor Inventory | Third-party vendor management and risk assessment |
Evidence
| Section | Purpose |
|---|---|
| Evidence | Unified evidence workspace — scoping, tracking, review, and dashboard |
Operations
| Section | Purpose |
|---|---|
| Task Management | Track evidence collection and implementation tasks |
| Systems Registry | Register systems that provide evidence |
| User Management | Manage organisation members and roles, and define teams |
Teams live on the Team Management card inside User Management. A team names who owns a piece of compliance work — a primary owner, an optional delegate to cover for them, and any number of members — and maps to one of fourteen platform-defined business functions. Teams record ownership only; they do not change anyone’s permissions. See Teams.
Documents
| Section | Purpose |
|---|---|
| Generated Documents | Policies and standards generated from your scoped controls |
Admin
| Section | Purpose |
|---|---|
| Engagements | Manage client engagements |
| Webhooks | Configure webhook integrations |
| Audit Log | Field-level change audit trail |
| Catalog Changelog | What changed between catalogue versions |
| Consultant Portal | Multi-client management for GRC consultants |
| Org Settings | Organisation configuration and API keys |
Platform — visible to platform administrators only
| Section | Purpose |
|---|---|
| Catalog | Platform-wide catalogue administration |
| Tenants | Manage the organisations on this deployment |
Consultant Portal is also role-gated, so it appears only where the role allows it.
Header Bar
Section titled “Header Bar”The header displays:
- Current section name — shows which area you’re in
- Organization selector — switch between organizations (if applicable)
- Refresh control — the “Updated 3m ago” caption, the “Updates available” flag, and the refresh button itself
- Notifications — the bell
- User menu — account options and sign out
Main Content Area
Section titled “Main Content Area”The central workspace changes based on your selected section. Most list views share one pattern:
- Filter sidebar — collapsible, down the left
- Search — in the toolbar above the list
- Detail pages — click a row and it opens full-width, with a breadcrumb back to the list and
←/→to step through neighbouring records
Quick Orientation
Section titled “Quick Orientation”Here’s a suggested path for new users:
1. Start with the Control Library
Section titled “1. Start with the Control Library”The Control Library is your reference for all available SCF controls. Here you can:
- Browse controls by domain (Access Management, Data Security, etc.)
- Search for specific controls by ID or keyword
- View control details including requirements and related frameworks
2. Explore the Mapping Matrix
Section titled “2. Explore the Mapping Matrix”The Mapping Matrix shows how SCF controls map to various compliance frameworks (ISO 27001, SOC 2, NIST, etc.). This helps you understand:
- Which controls satisfy which framework requirements
- Coverage gaps across frameworks
- The unified nature of the SCF approach
3. Check the Dashboard
Section titled “3. Check the Dashboard”Once your organization has scoped controls, the Dashboard provides:
- Implementation status - How many controls are implemented vs. in progress
- Framework coverage - Compliance posture per framework
- Evidence automation potential - Which evidence can be collected automatically
What’s Next?
Section titled “What’s Next?”Now that you’re oriented, explore these guides based on your role:
- Scoping controls for your organisation? See Control Management
- Managing evidence collection? See Evidence Management
- Assessing organisational risks? See Risk Management
- Managing third-party vendors? See Vendor Management
- Understanding the Dashboard metrics? See Dashboard Overview
- Setting up who owns what? See Teams
- Connecting AI assistants? See AI Integration (MCP)
Keyboard Shortcuts
Section titled “Keyboard Shortcuts”The platform supports these keyboard shortcuts:
| Shortcut | Action |
|---|---|
R | Refresh data (same as the refresh button) |
← → | Previous / next record on a detail page — controls, scoping, evidence, tasks, systems, vendors |
Esc | Close a modal, or go back from a detail page to its list |
Enter / Space | Activate the focused list row |

