Community edition product scope.
The community site should prove real product depth, not list vague capabilities. These modules and screenshots are pulled from the actual platform experience.

Risks
Risk registers, scenarios, KRIs, tolerance statements, and treatment workflows.

Controls
Control libraries, SoA coverage, assessments, and testing workflows.

Policies
Policy lifecycle, approvals, exceptions, mapping, and acknowledgments.

Incidents
Incident registers, timelines, lessons learned, and links back to controls and assets.

Audits
Internal audits, findings, corrective actions, and verification loops.

Evidence
Evidence repository, request tracking, and coverage visibility across the platform.

ITSM
Asset records, change management, and operational context for GRC decisions.

Organisation
Organisation structures, departments, meetings, processes, and key personnel.
Approval workflow
AI can help. Humans still decide.
Community users get the full mutation approval pattern: suggestions become pending actions, reviewers approve or reject them, and the system keeps an auditable trace of what happened.

Executive dashboard

Risk register
