73 pages, grouped exactly as the product groups them — this page mirrors the sidebar you will see after signing in. 67 sit inside the module groups; the other 6 are Dashboard, Calendar, Tasks, Document Library, Help Center and Chatbot. Nothing here is on a roadmap.

| Page | What it does |
|---|---|
| Dashboard | "Mission Control" — a company-scoped landing page where a user reads current risk posture (AI briefing, heat map, overdue items) and drills into whatever needs attention. |
| Calendar | One GRC calendar overlaying auto-generated due dates from every module (audits, findings, BCP exercises, corrective actions, vendor/risk/control reviews, EU AI Act, change windows) with manual events. |
| Tasks | Read-only unified worklist aggregating every due-dated remediation item across six modules, overdue-first. |
| Document Library | Company/org-scoped repository with folder tree, versioned uploads, in-page preview, admin recycle bin. |
| Page | What it does |
|---|---|
| Risk Register | The enterprise risk register — create, score, treat, link and sign off individual risks, with a 5×5 heat map and per-risk deep-dive. |
| Risk Assessments | Run structured, company-scoped questionnaire assessments from a shared template catalog, then generate AI reports and extract risks from them. |
| Risk Treatments | Manage mitigation actions against risks — ownership, schedule, budget, progress. 3 tabs (All / My Treatments / Overdue); 13 columns, all sortable. 6 filters + header scope. |
| Top 10 Risks | Present the ten highest-scoring risks with a weighted multi-criteria evaluation view. 2 view modes (table / cards). 6 filters + clear-all; client pagination; sortable columns. |
| Principal Risks | The board-level principal-risk register (UK Corporate Governance Code Provision 28/29) with annual-report disclosure drafting and multi-signatory sign-off. |
| Threats | A threat catalogue (actors, techniques, sources) linkable to risks. 10 sortable columns. 5 filters; stat cards by status and trend; create/view/edit/delete with 17 fields including threat_actor, threat_type, source, last_observed, and mitre_tactic +… |
| Vulnerabilities | Vulnerability register with CVE/CVSS enrichment and remediation tracking, linkable to both risks and threats. |
| Risk Dashboards | Three role-oriented analytics views (executive / operational / financial). 3 switchable dashboards; company + department + ERM-category filters; date range; settings modal with configurable auto-refresh. |
| Risk Reports | Generate AI-written GRC reports from templates, stream them live, archive them, and control who can see each one. |
| Page | What it does |
|---|---|
| Controls | Register of implemented controls, grouped by the ISO/framework pack each came from, with an evidence/assurance case per control. |
| Objectives | Register of organisational objectives with progress %, KPI target/current, budget, multi-owner. |
| Audits | Full audit lifecycle — programme-driven planning, a guided question-by-question fieldwork wizard, findings management, and AI-generated reports. |
| Non-Conformances | Read-only NCR log listing non-conformances raised from incidents, with ISO clause reference. |
| Incidents | Incident register with full response lifecycle, RCA, CAPA, and bridges out to Non-Conformance, Change Management and Business Continuity. |
| Page | What it does |
|---|---|
| Dashboard | Third-party risk posture for one company — rating distribution, risk×criticality heatmap, programme progress, alert trend and four work queues. |
| Third Parties | Browse the shared the shared intelligence layer intelligence pool and add entries to this company's monitored list. |
| Third-Party Requests | Staff-submitted onboarding request, reviewed by an org admin; approval writes the vendor into the shared pool. |
| Monitored Third Parties | The company's curated monitored list with two-tier sign-off, ownership, tagging, scan-depth control and assessment launch. |
| Review Queue | Open continuous-monitoring alerts for the company's monitored third parties. One sortable alert table (5 columns, severity sorted as a rank not a string), aria-sort on every header, vendor-name prefix stripped from the title, row → dossier. |
| Fix Queue | Human adjudication of the low-confidence tail of the the shared intelligence layer Resolver Agent's identity corrections and the nightly duplicate-merge sweep. |
| Attack Surface | Pool-wide list of completed external-exposure scans, one row per domain. Client search over domain/entity, 6 sortable columns, dedup per domain keeping the highest-scoring completed scan, row → dossier. Grades A–E with contrast-corrected text colours. |
| Monitoring | The detailed continuous-monitoring feed — change alerts and posture swings with per-finding drill-down. |
| Supply Chain Map | Blast-radius and concentration risk across the intelligence graph, plus geographic concentration. |
| Manual Third Parties | Flat, org-wide registry of hand-entered third parties. Nothing from the shared intelligence pool. |
| Reconcile Manual | Identify hand-entered vendors that already exist in the shared intelligence pool and replace them with automated monitoring. |
| Third Party Assessments | Questionnaire engine — instantiate a template against a vendor, answer weighted questions, score it, run the internal + external (vendor portal) review workflow. |
| Credit Checks | Opt monitored third parties into paid Creditsafe checks on a chosen cadence, project annual spend live, review history and failure alerts. credit-settings (not in the sidebar) manages the per-company BYOK key and cost model. |
| Page | What it does |
|---|---|
| Dashboard | Board-level exposure across your own infrastructure, software and SaaS estate, with the advisories that drive it. |
| Copilot | A tenant-fenced conversational analyst that answers on your estate, vendors, exposure and forecasts — and only yours. |
| Estate Register | Declare your technology estate — systems and software components — from a curated catalog, per company. |
| Estate Security | Your declared estate matched to the live CVE/KEV corpus, per system, with KEV and critical alerting. |
| Threat Radar | Active adversary campaigns matched to your monitored vendors and to your own company, each scored on severity and likelihood and expandable to the companies it affects, alongside forward-looking predictive forecasts. |
| Action Queue | Estate CVEs, regulatory deadlines and intelligence signals as one prioritised action list. |
| Briefings | A per-company daily intelligence brief, synthesised through your estate and vendor watchlist. |
| News | The live news corpus rendered per company — relevance-tagged security news with estate and vendor context. |
| Threats | Live threat intelligence with mitigations, relevance-tagged per company and linked to adversary profiles. |
| Forecasts | Estate-specific forward attack chains with detection signals ready for your SOC — refreshed weekly, on demand, and the moment a new estate is synced. |
| Adversaries | 583 adversary profiles with full detail, linked from your threats and forecasts. |
| Regulatory | Regulatory deadlines and horizon-scanning, defaulting to your declared jurisdictions, with per-company tracking. |
| Geo Risk | 207 countries scored on the STEMPLES-Plus model — sortable table, heatmap, and rich country profiles with radar diagrams and sourced indicators. |
| Horizon Briefs | Strategic view — STEMPLES risk matrix, likelihood-by-impact grid, defender-vs-adversary trajectory and a full risk register. |
| Page | What it does |
|---|---|
| BCP Management | 6 stat cards, 9 module cards with live counts, BC Readiness gauge, top-5 Critical Functions, top-5 Upcoming Exercises, recent activity, quick actions. |
| Critical Assets | The asset register behind risk and continuity work — five category views, a 22-field record covering classification, ownership, location, value and recovery objectives, and straight-line depreciation on capital items. |
| Page | What it does |
|---|---|
| Dashboard | 9 click-through KPI tiles — open changes, drafts awaiting submission, pending my approval, scheduled next 7d, success rate 90d, emergency rate 90d, failed/rolled-back 90d, changes causing incidents 90d, overdue PIRs — the last four going alert-red when non-zero. |
| Change Register | 7 filters incl. source manual vs CI/CD, all applied client-side over the fetched list — all real. + New Change modal min(1100px,94vw) with Details + 4 full-size plan tabs, each showing a filled dot when written and a red * when a rollback… |
| My Approvals | Cards from /changes/approvals/pending. Per card: ref, title, type chip, risk chip, category, submitted time, proposed window, the user's own eligible tier(s), and a ✓/✗ readiness strip across implementation/test/rollback/comms + "rollback tested" so a decision can… |
| Change Calendar | Two views — Monday-first 42-cell grid and a list. Shared filters plus a 7-mode window range (Upcoming / Next 30 / Next 90 / Selected month / Past / Unscheduled / All) and a sortable date column. Freeze overlay on both views; |
| Settings | Per-user account settings. Profile update. Password change, with enforced complexity (minimum 8 characters; must contain uppercase, lowercase and numbers) and confirmation matching. |
| Page | What it does |
|---|---|
| AI Portfolio | 4 stat cards; Fund/Fix/Freeze three-column matrix with top-5 use cases and scores; proportional model-risk bar with legend; maturity gauge with a "Not Assessed → Start Assessment" fallback. 3 quick actions. |
| AI Use Cases | 6 stat cards. 9-column table; 4-tab modal (Basic Info, Classification, AI Models, Risk Score — the last two deliberately disabled on create with "Save first to link models"). |
| AI Models | 6 stat cards; 10-column sortable table. Unlike Use Cases this page fetches once and filters/sorts client-side, with an honest Showing {n} of {m} models — its search, filters and sort are real. |
| AI Maturity | 8-column sortable list with aria-sort; create modal with full or domain-specific type and a checkbox-card picker over the 8 domains; view modal with overall score, level, per-domain breakdown and priority improvements. |
| AI Risk Toolkit | A structured assessment across 32 risk items spanning the AI lifecycle, filterable by lifecycle stage, linkable to a use case or model, and worked through with named assessor, reviewer and DPO roles against published ICO practical-steps guidance. |
| EU AI Act | Classification Wizard: 6 steps — Introduction → Article 5 Prohibited Practices → GPAI check → High-Risk / Annex III → Value-chain role → Result, each with contextual help, auto-saved wizard… |
| FRIA (Article 27) | The fundamental rights impact assessment required by Article 27 of the EU AI Act, run as a guided workflow against a registered AI system and filed alongside its classification and model record. |
| Page | What it does |
|---|---|
| ESG Dashboard | Org-wide rollup of emissions by scope, pillar scores, framework document progress, goals, ESG incidents, alert bar. |
| Carbon Accounting | GHG-Protocol emissions register — log activity data, pick a factor, auto-calculate tCO2e, run a verification workflow. |
| ESG Metrics | Record period values against a catalogue of standard E/S/G metric definitions, with baseline/target/change tracking. |
| Materiality | Create a CSRD-style double-materiality assessment and score standard ESG topics on impact vs financial axes. |
| ESG Frameworks | Per-company, per-framework workspace showing framework documents to complete and metric coverage. |
| Goals & Targets | CRUD over ESG goals with baseline→current→target progress, derived status, SBTi/intensity metadata, computed milestone timeline. |
| Supply Chain ESG | Flat table of supplier ESG assessments with a create-only modal and a deep link into the TPRM vendor dossier. |
| ESG Reports | Generate AI-written ESG framework "master documents" per company via a streaming Claude call, then archive, view, download as DOCX, or delete. |
| ESG Guides | Static launcher of 7 cards opening pre-built framework how-to HTML guides in a new tab. |
| Page | What it does |
|---|---|
| AI ISO Documents | AI-generated compliance document production against a chosen framework, driven by interview questions and document templates. |
| ISO Training | Self-contained LMS shipping standard-specific courses as TypeScript data, with lesson player, module quizzes, progress tracking and PDF certificates. |
| ISO & Security Guides | Index of the HTML completion guides, categorised (Regulatory / Cybersecurity / ISO / platform). |
| Page | What it does |
|---|---|
| Help Center | Standalone documentation site serving all 58 guides with sidebar nav, TOC and a client-side router. |
| Chatbot | Persistent multi-conversation AI compliance assistant, optionally scoped to one standard, streaming Claude's reply token-by-token. |
No module is held back, and nothing on this page is an add-on except TPRM & vCISO.