Administration
Configure the organisation, users, roles, security, module access, provider integrations, Policy and Document behaviour, scoring models, notifications and AI availability.
Configure before you scale
A controlled configuration gives operational teams consistent permissions, thresholds, workflow behaviour and ownership across PurpleWASP.
Set organisation profile, security preferences and AI availability.
Create roles, map permissions and assign users using least privilege.
Configure governed document behaviour, quizzes, reminders and notifications.
Review Asset CIA scales, Risk criteria and module-specific governance settings.
Connect supported providers, test credentials and validate scheduled collection.
Test principal roles and end-to-end workflows before rollout.
Configure the platform
Establish the principal settings, access model and validation checks before operational rollout.
Connect and operate supported providers
Configure GitHub, Google Workspace, Microsoft, AWS and Qualys through the shared Integration Management control plane, then monitor scheduled collection and downstream evidence.
Connect GitHub, Google Workspace and other integrations
Configure supported GitHub, Google Workspace, Microsoft, AWS and Qualys connections, review readiness, choose optional auto-refresh and validate evidence.
OperationsOperate and troubleshoot integrations
Monitor jobs, run history and collection readiness, and troubleshoot provider connections, OAuth and evidence limitations.
Integration setup handbook
Customer-facing setup steps for connecting supported providers and reviewing evidence.
Treat configuration as a governed change
Changes to access, matrices, thresholds, document behaviour or AI availability can affect users and existing records.
- Test role changes with a non-administrator account.
- Review affected Asset and Risk values after CIA/model changes.
- Document appetite, tolerance and exception authority decisions.
- Validate module access and cross-module hand-offs before broad rollout.
- Treat provider credentials as secrets and verify worker/scheduler health before relying on automated evidence.
No guidance matches that search.