Administration guide

Configure the PurpleWASP platform

Set organisation, role, document, quiz, asset, risk and notification rules before operational teams begin using the platform.

Organisation Administrator Initial setup plus periodic review Updated 27 July 2026

1. Configure the organisation

Set company name, permitted email domain, country, sector, currency, locations and sensitivity labels. Review these values before using AI-generated content because location and sector can influence generated drafts.

2. Manage roles and users

Create organisation roles, map them to PurpleWASP system roles and assign users. Use least privilege and separate ownership, approval and exception-decision responsibilities where appropriate.

3. Configure documents, quizzes and reminders

Document settings control review periods, supported document types, templates, quiz availability and recall behaviour.
  • Set review periods and the reminder intervals leading up to review.
  • Configure document types, categories and templates.
  • Enable or disable quiz support for each document type.
  • Allow document recall where the submission has not yet been acted on.
  • Set quiz passing score, score visibility and review period.
Message settings control approval reminders, review reminders and other workflow notifications.

4. Configure assets

Manage the CIA scale, asset value bands, reassessment periods, asset classes and types, criticality labels, locations, location types, tags and custom controls.

Changing the CIA scale recalculates scores. Communicate the change and review affected risk thresholds and reports.

5. Configure risk

Risk settings include assessment SLAs, exception review periods, categories, acceptance criteria and FAIR financial thresholds.
  • Set assessment SLAs and reassessment intervals.
  • Set exception review periods and risk approver responsibilities.
  • Define risk categories and qualitative acceptance criteria.
  • Configure FAIR appetite, tolerance, currency and supporting baselines.

Verify the configuration

  • Create a test user for each principal role and verify access.
  • Create a sample document and confirm approval, quiz and publication rules.
  • Create a sample asset and confirm CIA calculation.
  • Send the asset to risk and validate appetite and tolerance behaviour.
  • Review notification timing in a controlled environment.

Common problems

A role can see too much or too little

Review both the organisation role and its mapping to system roles. Test with a non-administrator account.

Risk recommendations changed unexpectedly

Review qualitative acceptance criteria, appetite, tolerance and any recent matrix changes.