From sign-in to live GRC in about 15 minutes.
Five short steps take you from your welcome email to a platform that already knows what applies to you — with your controls, frameworks and obligations populated. Here’s the fastest path.
Five steps to a working platform.
Sign in and set your password
Open the link in your welcome email and choose a password (at least 12 characters, with an uppercase and a lowercase letter, a number and a symbol). That signs you in as your organisation’s super-administrator. If the link has expired, ask whoever provisioned your account to re-issue it.
Run the OCE setup wizard — the step that does the work
This is the one that turns an empty tenant into your platform. The Organisation Context Engine™ (OCE) asks who you actually are — your legal entities, the jurisdictions you operate in, your sectors and activities, and your size — and then computes exactly which regulations and obligations apply to you, each with its reasoning. Completing it populates your obligations, controls and frameworks along the Spine, so you’re not building from a blank page. Do this before anything else.
Add a second administrator
Invite a colleague as a second super-administrator. This meets the two-admin minimum (ISO 27001 A.5.15) and means you’re never locked out if one account is unavailable. Administration → Users & Roles.
Turn on multi-factor authentication
Under Administration → Security & MFA, enable MFA for your tenant (authenticator app). For a GRC platform holding your compliance evidence, this is worth doing on day one. You control whether it’s required for everyone and any grace period.
Invite your team
Add your colleagues and assign a role template that fits each of them — Head of Risk, Compliance Manager, Auditor, and so on. Everyone works on the same Core, so their work rolls up into one risk register, one evidence repository and one audit log.
A quick tour of your Core modules.
Everything runs on one Core — one identity, one evidence repository, one audit log. Here’s where each job lives.
| Compliance | Your obligations-to-assurance core: obligations, controls, regulations, frameworks, policies, attestation status, the Synergy Map and maturity. Start here after the OCE wizard. |
| Risk Management | The risk register through to appetite — configurable scoring, KRIs, scenarios, risk assurance, loss events and RCSA campaigns. |
| Governance | Governing bodies, the governance calendar, document library and stakeholders. |
| Audit & Assurance | Internal audit over the same control universe — plans, engagements and findings that trace back to obligations. |
| Third-Party Risk | Onboard and assess vendors — assessments, risk assessments, due diligence and questionnaires. |
| My Items | Your personal home — the tasks, approvals, policies to attest and training assigned to you, gathered in one place. |
| Administration | Organisation structure, business units, departments, users, roles & permissions, security & MFA, branding, reference data, integrations, your subscription and the pack catalogue. |
Domain packs (Ethics & Conduct, Financial Crime, Security & Privacy and more) are coming soon and switch on within the same Core when they’re released — nothing to re-build.