Everything you need to get started with PurpleWASP across policies, risks, assets and compliance.
1. Introduction
Welcome to PurpleWASP — an integrated governance, risk and compliance platform for managing policies, risks, assets, compliance obligations, evidence, users and reporting in one place.
Cover: PurpleWASP overview and navigation highlights.
1.1 What is PurpleWASP?
PurpleWASP helps organisations connect GRC activity that is often split across documents, spreadsheets and disconnected systems.
Policy Management — Draft, approve, publish and attest to policies with version control.
Risk Management — Record, assess, treat and monitor risks in a structured risk register.
Asset Management — Maintain an asset register with owners, custodians, lifecycle data and classification.
Quizzes & Engagement — Assign quizzes and measure user understanding of published content.
PurpAI Assistant — Summarise policies, draft quiz questions and support GRC queries.
Messaging & Notifications — Keep users informed about assignments, deadlines and review actions.
1.2 Who Should Use This Guide?
Admins who configure the platform, manage users, permissions and licensing.
Approvers who review and approve policies or assigned governance records.
Module Managers such as Policy Managers, Risk Managers, Asset Managers and Compliance Managers.
Users who read assigned content, complete tasks, take quizzes and manage their own profile.
1.3 System Requirements
Use a modern browser such as Chrome, Edge, Firefox or Safari.
You need an active PurpleWASP account and the correct role for your work.
Your organisation must have an active plan and enough seats for assigned users.
Two-factor authentication may be required depending on your organisation settings.
2. Getting Started
2.1 Logging In
Go to https://purplewasp.com and click Login.
Enter your email and password.
Complete 2FA if enabled.
Click Login to access your dashboard.
PurpleWASP login page.
2.2 Dashboard Overview
The dashboard is role-aware. You may see policy tasks, risk actions, asset ownership updates, compliance evidence requests, quiz deadlines, messages and notifications depending on your permissions.
Left navigation: Policies, Risks, Assets, Compliance, Quizzes, Users, Messaging and Settings.
Top-right: Notifications and account controls.
Bottom-right: PurpAI assistant.
Dashboard overview.
2.3 Profile & Security
All users can manage their own profile and security settings.
Update your name and password.
Enable or disable 2FA where your organisation permits it.
Keep account recovery details accurate.
3. Module Guides
3.1 Policy Management
Use Policy Management to control the full lifecycle of organisational documents.
Create policies from templates or blank documents.
Set metadata such as owner, type, review period, sensitivity and target audience.
Send drafts for review and approval.
Publish approved policies and assign them to users or groups.
Track acknowledgements, quizzes, review dates and version history.
3.2 Risk Management
Use Risk Management to identify, assess, treat and monitor organisational risks.
Add risks to the risk register with a title, category, description and owner.
Assess likelihood, impact and current risk level.
Record controls, treatment plans, action owners and due dates.
Review residual risk and update status as treatment progresses.
Link relevant assets, policies or compliance obligations where applicable.
3.3 Asset Management
Use Asset Management to maintain an accurate view of the assets that support your organisation.
Create assets manually or import them using the asset template.
Record ownership, custodian, location, asset type, lifecycle status and classification.
Use unique identifiers such as serial number or product number where available.
Track CIA values, vendor details, licensing information and tags where relevant.
Use asset data to support risk assessment and compliance scoping.
3.4 Compliance Management
Use Compliance Management to track requirements, controls, evidence and audit readiness.
Record compliance frameworks, obligations, controls or audit requirements.
Assign owners and due dates for control updates and evidence collection.
Upload evidence with notes, source details and review context.
Track compliance status, exceptions and remediation actions.
Reuse evidence where the same control supports multiple obligations.
3.5 Reporting & Dashboards
Reporting brings together activity from policies, risks, assets and compliance.
View completion and overdue items by module.
Monitor risk treatment progress and compliance evidence status.
Export data where your role and plan allow it.
Use dashboard summaries to prioritise the next action.
4. Role-Based Features
4.1 Admin Role
Admins manage the platform environment. They configure settings, users, roles, notifications and licensing.
Maintain company profile, logo, email domain, sector and security preferences.
Create organisation roles and map them to system permissions.
Manage users, groups, seat allocation and bulk imports.
Configure policy settings, quiz defaults, notifications and module-level settings.
Review access control and audit activity where available.
4.2 Approver Role
Approvers review submitted records before they move to the next lifecycle stage.
Review policy drafts and approve or reject with comments.
Review assigned compliance evidence or governance records where configured.
Track pending approvals and deadlines from the dashboard or module views.
4.3 Module Managers
Module Managers own day-to-day workflows in their assigned area.
Users complete assigned work and manage their own account settings.
Read and acknowledge assigned policies.
Complete assigned quizzes.
Respond to risk, asset or compliance tasks assigned to them.
Receive notifications and messages about deadlines or required actions.
5. Global Features
5.1 In-App Messaging
Receive alerts for unread messages, pending approvals, assigned tasks and upcoming deadlines.
Use the central inbox to keep module-related communications in one place.
Admins can configure reminder timing and notification behaviour.
5.2 PurpAI Assistant
PurpAI is an AI-powered assistant available from the chat icon.
Summarise policies into simpler language.
Generate quiz question drafts from policy documents.
Help draft risk descriptions, treatment ideas or compliance explanations.
Answer general GRC questions using available context.
6. Licensing
PurpleWASP plans may vary by seat count, module access, reporting depth, integrations and support level.
6.1 Understanding Plans
Free Plan
Small teams evaluating core workflows
Core policy features
Limited seats
Community support
Team Plan
Growing teams
Broader module access
Standard reporting
Email support
Business Plan
Operational GRC teams
Policies, risks, assets and compliance workflows
Integrations
Priority support
Enterprise Plan
Larger or regulated organisations
Advanced reporting and audit logs
API/SSO options
SLA-backed support and onboarding
6.2 Monitoring Usage
Admins can monitor current plan, seat usage and module access.
Warnings may appear when the organisation approaches a limit.
Inactive users should be reviewed before adding new seats.
6.3 Upgrading Your Plan
Plan upgrades are not self-service. Contact PurpleWASP Support with your organisation name, desired plan, required seats, modules and billing preference.
7. Support & Resources
7.1 PurpleWASP Support
Contact Support for login issues, technical issues, billing, module access or plan upgrades.
Include module name, screenshots, timestamps, affected record IDs and any visible error message.
Response times vary by subscription plan.
7.2 Knowledge Base
Use the Help Center for FAQs, troubleshooting, release notes and module walkthroughs.
Use Help Centre Guides & Templates for tutorials, role guidance and adoption checklists.
Use the Platform area to understand modules, connected workflows and implementation.
7.3 Organisation Admins
For role or permission changes, contact your organisation Admin first.
Admins control user role mapping, account status, group assignments and module access.