Skip to content

Getting Started

Getting started illustration

This guide walks you through your first login and helps you understand the platform’s main areas. By the end, you’ll know how to navigate the interface and where to find key features.

How you sign in depends on how your deployment is configured — see Authentication for the full picture.

  • Default self-hosted install (API key): navigate to your platform URL — the app authenticates with the deployment’s configured API key and takes you straight to the Control Library. Nothing to click.
  • OIDC single sign-on: the Sign in button redirects you to your organization’s identity provider (the bundled Keycloak or your own IdP) — see Identity Provider.
  • Google Sign-In (when enabled): click Sign in with Google and select your account (use your work account if applicable).

The platform has three main areas:

The collapsible sidebar on the left provides access to all platform sections. Hover over it to expand and see labels. Sections are grouped by function:

Overview

SectionPurpose
DashboardOverview of your compliance posture
AnalyticsCapability Posture — security implementation by KSI theme

Controls & Frameworks

SectionPurpose
Control LibraryBrowse all 1,451 SCF controls
Framework MappingsView framework-to-control mapping matrix
Control ScopingScope controls and identify framework coverage gaps

Risk & Third Party

SectionPurpose
Risk Register5x5 risk matrix and risk assessments
Vendor InventoryThird-party vendor management and risk assessment

Evidence

SectionPurpose
EvidenceUnified evidence workspace — scoping, tracking, review, and dashboard

Operations

SectionPurpose
Task ManagementTrack evidence collection and implementation tasks
Systems RegistryRegister systems that provide evidence
User ManagementManage organisation members and roles, and define teams

Teams live on the Team Management card inside User Management. A team names who owns a piece of compliance work — a primary owner, an optional delegate to cover for them, and any number of members — and maps to one of fourteen platform-defined business functions. Teams record ownership only; they do not change anyone’s permissions. See Teams.

Documents

SectionPurpose
Generated DocumentsPolicies and standards generated from your scoped controls

Admin

SectionPurpose
EngagementsManage client engagements
WebhooksConfigure webhook integrations
Audit LogField-level change audit trail
Catalog ChangelogWhat changed between catalogue versions
Consultant PortalMulti-client management for GRC consultants
Org SettingsOrganisation configuration and API keys

Platform — visible to platform administrators only

SectionPurpose
CatalogPlatform-wide catalogue administration
TenantsManage the organisations on this deployment

Consultant Portal is also role-gated, so it appears only where the role allows it.

The header displays:

  • Current section name — shows which area you’re in
  • Organization selector — switch between organizations (if applicable)
  • Refresh control — the “Updated 3m ago” caption, the “Updates available” flag, and the refresh button itself
  • Notifications — the bell
  • User menu — account options and sign out

The central workspace changes based on your selected section. Most list views share one pattern:

  • Filter sidebar — collapsible, down the left
  • Search — in the toolbar above the list
  • Detail pages — click a row and it opens full-width, with a breadcrumb back to the list and / to step through neighbouring records

Here’s a suggested path for new users:

The Control Library is your reference for all available SCF controls. Here you can:

  • Browse controls by domain (Access Management, Data Security, etc.)
  • Search for specific controls by ID or keyword
  • View control details including requirements and related frameworks

The Mapping Matrix shows how SCF controls map to various compliance frameworks (ISO 27001, SOC 2, NIST, etc.). This helps you understand:

  • Which controls satisfy which framework requirements
  • Coverage gaps across frameworks
  • The unified nature of the SCF approach

Once your organization has scoped controls, the Dashboard provides:

  • Implementation status - How many controls are implemented vs. in progress
  • Framework coverage - Compliance posture per framework
  • Evidence automation potential - Which evidence can be collected automatically

Now that you’re oriented, explore these guides based on your role:

The platform supports these keyboard shortcuts:

ShortcutAction
RRefresh data (same as the refresh button)
Previous / next record on a detail page — controls, scoping, evidence, tasks, systems, vendors
EscClose a modal, or go back from a detail page to its list
Enter / SpaceActivate the focused list row