Quick Start by Scenario
Use this guide when you are new to administering the platform or need a short operating plan for the first review cycle.
Start Task Shortcuts
| Task | Open |
|---|---|
| Find the right guide for a specific task | How Do I Task Index |
| Set up users, roles, departments, and workflows | Tenant Setup Order, Admin Operations Runbook |
| Run a compliance assessment | Compliance and Assessments, Assessment Playbooks |
| Manage a high or critical risk | Risk Management, Workflow and Status Reference |
| Publish a policy | Governance |
| Onboard vendors and assets | Third Parties and Assets |
| Prepare reports for management | Reports and Analytics |
1. First 30 Minutes
Goal: understand immediate health and urgent work.
- Open the dashboard.
- Review critical risks, overdue issues, pending approvals, and expiring exceptions.
- Open Reports and review KPI cards.
- Check whether any high-priority item has no owner.
- Open the assessment list and identify overdue or stalled assessments.
- Open the risk register and filter high and critical residual risks.
- Write down the top five items needing attention.
Output:
- immediate triage list
- owners to contact
- items requiring escalation
2. First Day
Goal: confirm ownership, access, and urgent workflows.
- Review users and roles for the main admin, compliance, risk, control owner, auditor, and executive roles.
- Confirm department assignments for active users.
- Review pending approvals and identify blocked approvers.
- Review overdue issues, findings, and assessments.
- Review critical risks and confirm each has an owner, treatment decision, and review date.
- Review policies pending approval or acknowledgement.
- Review vendors and assets without owners or criticality.
Output:
- access and ownership corrections
- approval follow-up list
- overdue work list
- critical risk follow-up list
3. First Week
Goal: stabilize administration and reporting.
- Clean up duplicate departments, categories, or lookup values.
- Reassign records owned by inactive or incorrect users.
- Review evidence quality for active assessments.
- Confirm non-compliance follow-up decisions: risk, issue, finding, exception, or accepted gap.
- Review high-risk vendors and critical assets.
- Review scheduled reports and remove reports without a clear owner or audience.
- Prepare a short management update.
Output:
- clean ownership model
- first data quality improvements
- management summary
- list of decisions needed
4. First Monthly Review
Goal: run a complete governance review cycle.
- Review dashboard period movement.
- Review compliance score and major assessment changes.
- Review high and critical risks, treatment progress, and appetite breaches.
- Review overdue audit findings and issues.
- Review policies due for review and acknowledgement gaps.
- Review expiring exceptions.
- Review high-risk vendors and critical assets.
- Review KPI breaches and explain the source cause.
- Validate report filters and source data.
- Export the management report pack.
Output:
- monthly GRC health summary
- risk and compliance decisions needed
- overdue work escalation list
- data quality action list
5. Before an Audit
Goal: prepare reliable evidence and reduce review delays.
- Confirm audit scope and period.
- Review related frameworks, controls, assessments, and policies.
- Check evidence quality for sampled controls.
- Ensure open findings have owners, due dates, and remediation notes.
- Export assessment, policy, risk, and finding reports as needed.
- Prepare explanations for accepted risks and policy exceptions.
- Confirm all evidence is current and relevant.
Output:
- audit evidence pack
- known gaps list
- remediation and exception summary
6. Before an Executive Meeting
Goal: provide a concise management view.
- Review dashboard trends.
- Review KPI status and explain critical or at-risk indicators.
- Summarize critical risks and decisions required.
- Summarize compliance score movement and major non-compliance.
- Summarize overdue issues and findings.
- Summarize exceptions expiring soon.
- Validate all report filters.
- Export only the reports needed by the audience.
Output:
- executive summary
- decisions required
- owner action list
- report pack
7. New Department Onboarding
Goal: bring a department into the governance operating model.
- Create or confirm the department name.
- Add users and assign correct roles.
- Identify department control owners, risk owners, policy owners, vendor owners, and asset owners.
- Assign existing records to the department where appropriate.
- Launch required assessments or evidence requests.
- Review department risks, vendors, and assets.
- Add the department to relevant policy acknowledgement campaigns.
Output:
- department access and ownership setup
- initial assessments and assignments
- department-level risk and compliance view
8. New Administrator Handover
Goal: transfer administration without losing context.
- Review active users, roles, departments, and workflows.
- Review open assessments, critical risks, overdue issues, findings, policies, exceptions, vendors, and reports.
- Review scheduled reports and their recipients.
- Review known data quality problems.
- Review current management commitments and pending decisions.
- Confirm who can approve access changes and workflow decisions.
Output:
- admin handover checklist
- current issues list
- decision and escalation map