Skip to content

Collections

A collection is a named bag of GRC objects. It has no status, no schedule and no lifecycle of its own — those belong to the things inside it. What it gives you is a stable handle on “these objects, together”, which is exactly what a project needs for its scope and an accreditation needs for its dossier.

Project management → Collections in the sidebar. Create a collection opens the form.

Anything that can sit in a project’s scope can sit in a collection:

  • Audits
  • Risk assessments
  • Quantitative risk studies
  • EBIOS RM studies
  • Entity assessments (third-party reviews)
  • Findings binders
  • Evidences
  • Security exceptions
  • Policies

The collection itself carries only an ID, a Domain, Labels, an Observation and those relationships. The observation is a free Markdown note — use it to record why the bundle exists and who curates it; it shows on the detail page only, not in the list.

The detail page shows the header — name, ID, domain, labels, observation and the standard actions — then one tab per category that has something in it, sorted alphabetically. Each tab is a filtered table of those objects, with the same columns and behaviour as the standalone list page.

Two small buttons at the top right of each tab control what goes in:

ButtonWhat it does
SelectOpens a picker of existing objects of that type; tick one or many to attach them
AddOpens the normal creation form for that type, pre-scoped to this collection

Use Select when the object already exists and you just want it in scope; use Add when you need to create it from scratch.

A collection is just a bag, so several things can point at the same one and one object can belong to several collections. The common patterns:

  • Project scope — one collection per project, grown as the project pulls in more work. This is the default arrangement.
  • Accreditation dossier — an accreditation links to a collection holding the audits, evidences and exceptions that justify it, and surfaces all of them on its page as Associated objects.
  • Ad-hoc roll-ups — a regulator pack, a board-meeting bundle, “everything in flight this quarter”. Create a collection, fill it, use it, keep it or drop it.