Skip to content

Set Up a New Organization

Goal: configure the guardrails once so every package after benefits. Order matters mildly; each step makes the next more useful. "Good enough to start" is the bar; everything here can be refined later.

1. Technology Catalog

The most consequential setting: what generation may select. The seeded reference library works day one; spend twenty minutes marking what you actually run as in use, adding your standards, and setting anything banned to forbidden. (Catalog)

2. Control Frameworks

NIST 800-53 comes seeded. Add the frameworks your audits actually cite (HIPAA, PCI DSS, SOC 2) so package-level regulation choices have teeth. (Regulations and controls)

3. Vendor Contracts

Enter your real agreements: renewal dates and discounts especially. Generation starts leveraging them immediately, and renewal risk gets watched from here on. (Vendor contracts)

4. Members and Roles

Invite the team with least-privilege roles: architects design, reviewers judge, viewers follow. (Members, teams, and roles)

5. Integrations (Medium+)

Connect Jira or Azure DevOps under a service account, and test the connection. (Integrations)

6. ROI Rates

One honest calibration of workstream rates makes every package's value figure defensible. (ROI settings)

7. If You Are Large-plan

Discovery with read-only credentials, SIEM export to your security stack, and single sign-on from your IdP.

Then Prove the Setup

Run Your First Approved Design end to end. Where it pauses is exactly where your setup wants another pass.