Feature flags
Feature flags turn whole product areas on or off. They are how you tailor the sidebar and the surface area of CyberGuard to what your team actually uses, and how you keep specialised or experimental modules out of sight until you want them. A flag affects what appears in the navigation, which pages are reachable and which permissions are even relevant — it never deletes data. Turning a flag off hides the feature; turning it back on restores it exactly as it was.
Where to find it
Section titled “Where to find it”Extra → Settings → Feature flags. You need administrator rights on the global domain to change them. After saving, do a hard refresh in the browser so the sidebar rebuilds.
The toolbar
Section titled “The toolbar”A sticky toolbar sits above the groups:
- Search filters the grid by flag name or description.
- The counter reads “N of M enabled” so you can see at a glance how much of the platform is switched on.
- Enable all and Disable all act on every flag; each group card also has its own check and cross buttons that act on that group only.
- Reset to defaults restores the shipped defaults listed in the tables below.
Presets
Section titled “Presets”Three presets re-shape the whole grid in one click. A preset is an explicit ON-set: every flag it does not list is turned off, so a preset is a replacement, not an addition. Review the result before saving.
| Preset | What it configures |
|---|---|
| Minimal | Bare-bones compliance and core operations only. |
| Compliance-focused | Audits, findings, reports and governance; risk and privacy extras off. |
| Risk-focused | Risk, EBIOS RM, quantitative risk and business impact analysis; compliance extras lighter. |
Flag reference
Section titled “Flag reference”Flags are grouped in the interface exactly as below.
Organization
Section titled “Organization”| Flag | Default | What it enables |
|---|---|---|
| Objectives (ISO) | On | The organisational objectives register. |
| Issues (ISO) | On | The organisational issues register. |
| Journeys | On | The presets and journeys section for guided onboarding workflows. |
| Custom portals | Off | The Manage portals surface, internal portals and the public trust center. |
Catalog
Section titled “Catalog”| Flag | Default | What it enables |
|---|---|---|
| Security advisories | On | The security advisories catalogue. |
| CWE | On | The catalogue of software weaknesses (CWE). |
Operations
Section titled “Operations”| Flag | Default | What it enables |
|---|---|---|
| Tasks | On | One-shot and recurring tasks. |
| Control Plan | On | The aggregated view of recurrent task completion across periods. |
| X-rays | On | The inconsistency-detection page. |
| Incidents | On | Security incident tracking. |
| Findings tracking | On | Findings management for pentests, internal audits and reviews. |
| Metrology | On | Metric definitions, instances and custom dashboards. |
Management and Governance
Section titled “Management and Governance”| Flag | Default | What it enables |
|---|---|---|
| Project management | Off | Generic collections, accreditations, projects and responsibility matrices. |
| Reports | Off | Custom reports built on your data. |
| Third party | On | Third-party entities, representatives, solutions and entity assessments. |
| Contracts | Off | Contracts and agreements inside third-party risk. |
| Validations | Off | Configurable approval workflows on objects that warrant sign-off. |
| Workflows | Off | Automation on a schedule, an event or a webhook. |
| Policy document editor | On | The built-in markdown editor for policies, with versioning, review and PDF export. |
| Document management | On | The standalone document catalogue, templates and object classifications. |
| Exceptions | On | Exception and derogation tracking. |
Compliance
Section titled “Compliance”| Flag | Default | What it enables |
|---|---|---|
| Compliance | On | Compliance assessments (audits). Effectively the master switch for the compliance pillar. |
| Assignment/Respondent mode | On | Requirement assignments and the respondent surface. |
| Advanced Analytics | On | The per-audit analytics dashboard (compliance by section, controls coverage, timeline). |
| Domain-tree audit inheritance | Off | Combining an audit’s results with parent-domain audits on the same framework. |
| Technical postures | Off | Measuring assets against technical baselines with recurring results. |
Risk management
Section titled “Risk management”| Flag | Default | What it enables |
|---|---|---|
| Risk acceptances | On | Risk acceptance decisions and approvals. |
| Inherent Risk | Off | Inherent-risk columns alongside current and residual risk. |
| Vulnerabilities | On | Vulnerability tracking. |
| EBIOS RM | On | EBIOS Risk Manager studies. |
| CRQ studies | On | Quantitative risk studies and simulations. |
| Threat modeling | Off | Attack sequences built over a TTP catalogue and wired to risk scenarios. |
| TTP catalogs | Off | Adversary tactics and techniques catalogues. |
| Scoring assistant | On | Scoring a scenario from threat-agent and vulnerability factors. |
| Business Impact Analysis | On | Business impact analyses and continuity planning. |
GDPR / Privacy
Section titled “GDPR / Privacy”| Flag | Default | What it enables |
|---|---|---|
| Privacy | On | The privacy register pillar (master switch). |
| Personal Data | On | The personal-data inventory and its classification. |
| Purposes | On | The purposes register. |
| Right Requests | On | Data-subject rights requests. |
| Data Breaches | On | Data-breach records and notifications. |
| Flag | Default | What it enables |
|---|---|---|
| SSO auto-provisioning (JIT) | Off | Auto-creating an account on a user’s first SSO login, plus the related SSO settings. |
| Terminologies | On | Organisation-specific label overrides. |
| Webhooks | Off | Outgoing webhooks and the Webhooks settings tab. |
| Comments | On | Comments on supported objects. |
| Experimental | On | The experimental area, including the Data Wizard. |
Related
Section titled “Related”- Settings — the other tabs on the same page.
- Auditee mode and portals — two flag-gated surfaces documented in detail.
- Outgoing webhooks — configuring endpoints once the flag is on.
