Resources

Documentation, method, and where to ask. Listed only where it exists.

Most material is provided during your engagement and onboarding rather than published here. This page says which is which, and each item names where it lives.

Product documentation

What is written down

Documentation is delivered to the people who evaluate the product and the people who run it, rather than kept in a public library. Everything listed here exists, and each item names where it lives.

  • The four-step workflow, the separated decision dimensions, export behaviour and how reassessment is governed.

  • Where the control library comes from, how precedence is recorded, and what a registered source does and does not mean.

  • Tenant boundary, invitation-controlled membership, enterprise identity, the two authorization gates and the audit model.

  • Workspace and administration guide

    Provided during onboarding

    Organization setup, roles and permissions, invitations, identity connections, and the audit and notification views available to administrators and auditors.

  • Guided assessment walkthrough

    Provided during your engagement

    A run through scoping, profiling, decision recording, review and export against synthetic data, with your own solution types in mind.

Assessment method

Notes on the method

The method is the product. These notes describe how scope is derived and how decisions are kept apart, in enough detail to be argued with rather than admired.

  • Scoping model

    Provided during your engagement

    How the asset group and subgroup link sets the authoritative initial scope, where conditional risk tiers apply, and the fixed order in which later overlays are allowed to act.

  • Solution profile reference

    Provided during your engagement

    Every fact the profile records, and which review signal each fact can raise. Signals are prompts for a person, and the reference says so field by field.

  • Decision model and maturity scale

    Provided during your engagement

    Applicability, implementation, design and operating effectiveness, and the maturity scale from 0 Absent to 5 Optimizing, with the rule that keeps each of them from inheriting another.

  • Source assurance record

    Provided during your engagement

    How sources are registered, versioned, mapped, re-verified and bounded, including the review work that is still open rather than only the part that is finished.

  • The shortest honest version of all of the above, written for an evaluator who has fifteen minutes.

Release notes

Release and change records

Release records are provided to customers with their workspace, and a public changelog begins with general availability. Change that affects an assessment is handled inside the workspace as governed work, so it reaches the people who have to act on it.

  • Public release feed

    At general availability

    The public changelog begins with general availability, so it will describe availability rather than activity. Release information reaches customers through the workspace it affects.

  • Baseline change reaches you as work

    In the product

    When a newer internal baseline takes effect, every affected assessment raises an owned, dated decision inside the workspace with recorded rationale. A change that matters to your results arrives as an assigned action, not as a newsletter you have to read.

  • Release and change records for your organization

    Provided during onboarding

    Release detail relevant to an activated workspace is shared with the organization administrators responsible for it.

Contact

Where to ask

Every route below goes somewhere real. Access requests, access problems and procurement questions each have their own path, so a question reaches the person who can answer it rather than a general inbox.

  • The route for evaluation, pilot discussion, security review and procurement questions. Describe the scope you need to assess and who would be nominated as your first organization administrator.

  • Access help

    On this site

    For a pending invitation, a missing membership, the wrong account, a suspended membership, an expired session or an expired entitlement.

  • Security and procurement review

    Provided during your engagement

    Assurance evidence, questionnaires and diligence are handled as part of the access request rather than through a separate inbox.

  • Existing members enter their organization workspace through the application. This explainer says what signing in settles, what it does not, and where authentication happens. The website never authenticates anyone and never creates a membership.

Next step

Ask for what you need

Request the material that matters to your review. Documentation, method notes and assurance evidence are shared through the access request.