Practical guidance for real platform work.
Follow current workflows for Policy & Document Management, Assets, Risks, Controls, provider integrations, ISO 27001, SOC 2, Cyber Essentials/Plus, NIST CSF 2.0, CIS Controls v8.1, Third-Party Risk, PurpAI and platform administration.
Complete the workflows that connect the platform
Start with the most common governance, assurance and risk activities.
Prepare for SOC 2
Manage scope, criteria, Control coverage, evidence, testing, remediation and audit readiness without confusing readiness with the independent auditor opinion.
Operate NIST CSF 2.0
Build Current and Target Organizational Profiles, reuse shared Controls, analyse gaps and manage improvement actions and Implementation Tiers.
Implement CIS Controls v8.1
Select an Implementation Group, resolve Safeguard Control coverage, reuse assurance and prioritise improvement work.
Prepare for Cyber Essentials
Complete the questionnaire and five technical areas, resolve readiness gaps and prepare the Cyber Essentials Plus technical-assurance workflow.
Create a governed document
Classify the document, complete metadata and move it into the approval workflow.
Adopt and scope Controls
Bring catalogue Controls into your organisation and establish where they apply.
Discover and onboard third parties
Convert vendor references already found in Assets into governed TPRM relationships.
Connect GitHub, Google Workspace and other integrations
Configure supported providers centrally, test access, activate capabilities and validate manual and scheduled collection.
Use PurpAI to navigate and launch work
Move from a conversational result to the exact authorised record or supported workflow without bypassing module controls.
Choose where you are working
Each workspace page explains its lifecycle and links to task-level guidance. PurpAI and analytics operate across those workspaces rather than replacing them.
Policy & Document Management
Create, approve, publish, distribute, review and version governed documents.
Asset Management
Maintain ownership, taxonomy, CIA value, lifecycle and the Asset context used by Risk and TPRM.
Risk Management
Assess qualitative and FAIR scenarios, apply treatment and govern exceptions and reassessments.
Control Management
Adopt Controls, resolve applicability, track implementation and perform assurance.
Compliance
Operate ISO 27001, SOC 2 readiness, Cyber Essentials/Plus, NIST CSF 2.0 and CIS Controls v8.1 with shared Control assurance and framework-specific readiness/gap workflows.
Third-Party Risk Management
Discover, tier, assess, assure, review and monitor external relationships and services.
PurpAI
Use contextual guidance, authorised live data, exact-record navigation, workflow launching, safe drafting and Suggested Attention.
Dashboards & Analytics
Interpret module dashboards, trends, deadlines and cross-module posture.
Administration
Configure users, roles, security, provider integrations, workflows, scales, criteria and organisation settings.
No Help Centre guidance matches that search.