Help Centre workspace

Administration

Configure the organisation, users, roles, security, module access, provider integrations, Policy and Document behaviour, scoring models, notifications and AI availability.

Start with the workflow

Configure before you scale

A controlled configuration gives operational teams consistent permissions, thresholds, workflow behaviour and ownership across PurpleWASP.

1
Organisation

Set organisation profile, security preferences and AI availability.

2
Access

Create roles, map permissions and assign users using least privilege.

3
Workflow

Configure governed document behaviour, quizzes, reminders and notifications.

4
Models

Review Asset CIA scales, Risk criteria and module-specific governance settings.

5
Integrations

Connect supported providers, test credentials and validate scheduled collection.

6
Validate

Test principal roles and end-to-end workflows before rollout.

Administrator guidance

Configure the platform

Establish the principal settings, access model and validation checks before operational rollout.

Integration Management

Connect and operate supported providers

Configure Microsoft Entra ID and Qualys through the shared Integration Management control plane, then monitor scheduled collection and downstream evidence.

Implementation documentation

Integration implementation and engineering references

Download the rollout, technical, operational and provider-development documentation for the shared integration architecture.

Important operating rules

Treat configuration as a governed change

Changes to access, matrices, thresholds, document behaviour or AI availability can affect users and existing records.

  • Test role changes with a non-administrator account.
  • Review affected Asset and Risk values after CIA/model changes.
  • Document appetite, tolerance and exception authority decisions.
  • Validate module access and cross-module hand-offs before broad rollout.
  • Treat provider credentials as secrets and verify worker/scheduler health before relying on automated evidence.