Administration guide

Configure the PurpleWASP platform

Set organisation context, security, users, roles, governed document, Asset, Risk, notification and module-access rules before operational rollout, including business objectives/processes used by Setup & Readiness and framework scoping.

Organisation Administrator Initial setup plus periodic review Updated 18 September 2026

1. Configure the organisation and security baseline

Set organisation profile information such as name, permitted domain, country, sector, currency, locations and sensitivity labels. Review account-security options and confirm whether organisation AI features should be available.

Use Setup & Readiness to maintain the wider GRC context used by downstream work where available, including business objectives, business processes and process-to-Asset dependencies. These records give framework scope and governance decisions a reusable organisation context instead of repeating the same description in each module.

Use real organisation context. Profile and GRC-context data can influence scoping, AI-assisted drafting and how users interpret governance records, so keep it current.

2. Manage roles, users and permissions

Create organisation roles, map them to PurpleWASP system permissions and assign users. Use least privilege and separate ownership, approval, exception and administrative responsibilities where appropriate.

  • Test the actual permissions of each principal role.
  • Remove stale or conflicting assignments.
  • Use named ownership rather than shared administrator responsibility for operational records.

3. Configure Policies, documents, quizzes and reminders

Document settings govern review periods, active document types, templates, quiz behaviour and related workflow options.
  • Review active document types and the capabilities each type supports.
  • Set review periods and reminder intervals.
  • Configure templates and quiz settings such as passing score and due periods where used.
  • Review recall behaviour and workflow notifications.
  • Confirm organisation AI availability before relying on AI document summaries or quiz generation.
Notification settings support approval, review and other workflow reminders.

4. Configure Assets

Review the CIA scale, Asset value bands, reassessment periods, taxonomy, criticality labels, locations, tags and related Asset settings used by your deployment.

Changing the CIA model can change calculated values. Communicate the change and review affected Asset and Risk priorities after the new model is applied.

5. Configure Risk

Risk settings include governance criteria such as assessment timing, exception review, categories, acceptance criteria and FAIR financial thresholds.
  • Set assessment and reassessment expectations.
  • Set exception review periods and decision authority.
  • Define qualitative Risk categories and acceptance criteria.
  • Configure FAIR appetite, tolerance, currency and supporting baselines where FAIR is used.

6. Confirm module access and ownership

Review who can view and manage Control Management, Compliance and Third-Party Risk Management. Confirm that each workspace has accountable owners before enabling wider access.

  • Control owners should understand applicability, implementation and assurance responsibilities.
  • Compliance roles should own the relevant framework workspace—for example ISO 27001 ISMS/SoA work or SOC 2 readiness and audit-preparation activity.
  • TPRM should have clear relationship, business, procurement and review ownership.
  • PurpAI should be treated as an assistant over authorised data and workflows, not as a replacement for module permissions, review or confirmation controls.

Verify the configuration

  • Sign in as a test user for each principal role and verify access.
  • Create a sample governed document and confirm approval, publication and quiz behaviour.
  • Create a sample Asset and confirm classification and CIA calculation.
  • Send the Asset to Risk and validate appetite/tolerance behaviour.
  • Adopt a sample Control and confirm the expected scope/implementation workflow.
  • Confirm a Compliance/SoA user can access the intended records without unintended administrative rights.
  • Run TPRM discovery on controlled sample data and confirm candidates require an explicit decision.
  • Where AI is enabled, confirm PurpAI only exposes authorised records and that workflow actions remain constrained by the test role's view/write permissions and confirmation requirements.

Common problems

A role can see too much or too little

Review both the organisation role and the mapped system/module permissions. Test with a fresh non-administrator login.

Risk recommendations changed unexpectedly

Review qualitative acceptance criteria, appetite, tolerance and any recent CIA/matrix changes.

PurpAI is unavailable

Confirm that organisation AI features are enabled and that the user has access to the module/context being queried.