Projects
A project is the unit you use to plan a piece of security work and track it to completion — a certification push, a tooling rollout, a remediation programme. It records the charter, the schedule, the money, the people, and the GRC objects the work actually touches, so the initiative has one page instead of living in a slide deck.
Where to find it
Section titled “Where to find it”Project management → Projects in the sidebar. Create a project opens the form.
Portfolio, programme or project
Section titled “Portfolio, programme or project”Every record carries a Kind — Portfolio, Programme or Project — and projects nest through a Parent project, so a portfolio rolls up programmes which roll up projects. Kind is an organisational hint: it changes the icon and the colour accent, and portfolios do not show the Scope tab. It unlocks nothing else, and you can change it later.
The detail page
Section titled “The detail page”The record opens as a single card: a header strip with the kind badge, name and ref ID; four KPI tiles; an info row with owner, sponsor, parent project and sub-projects; then seven tabs. Each section has its own Edit button and you edit one section at a time, with Save and Cancel at the top right.
| Tab | What you maintain there |
|---|---|
| Overview | Status, Health, Priority, Progress |
| Charter | Purpose, Objectives, Success criteria, Business case, Approval requirements, Exit criteria, Organisational alignment — all Markdown |
| Tracking | Schedule, financials and tolerances |
| Scope | Deliverables, Assumptions, Constraints, Dependencies. Not shown on portfolios |
| Linked | The linked collection, responsibility matrices and labels |
| People | Owner (day-to-day lead) and Sponsor (owns the business case) |
| Analytics | KPI cards plus lifecycle, progress and financial charts over time. Read-only |
Status and Health values come from Terminologies, so you can rename them to your own vocabulary. Priority runs P1 to P4 and Progress is a 0–100% slider in steps of 5. Setting the status to the built-in closed value stamps Closed at with today’s date automatically; moving it back out clears the date.
Tracking money
Section titled “Tracking money”The Tracking tab holds the Schedule (start date, end date, ETA, closed at), the Financials — Expected budget, Actual cost and a currency that defaults to the parent project’s, then to the instance setting — and Tolerances, the pre-agreed margins that signal when an initiative should be escalated.
The budget here is deliberately the high-level envelope a sponsor signed off, not a roll-up. The detailed build-versus-run picture lives on the applied controls attached to the audits, risk studies and findings inside the project’s collection. When the two numbers diverge, that gap is itself worth a conversation — the platform surfaces both sides and leaves the reconciliation to you.
Scope comes from a collection
Section titled “Scope comes from a collection”Creating a project automatically creates a collection named after it and links it on the Linked tab. That collection is the bag holding the audits, risk studies, findings binders, evidences and policies in scope — see Collections. You can swap it for a different collection later.
Related
Section titled “Related”- Collections — the project’s scope envelope.
- Responsibility matrices — who does what.
- Accreditations — the formal authorisation a project may be driving towards.
