Skip to content
Foxx Cyberfoxxcyber/docs

Monitoring and Your Calendar Feed

See every review, re-check, approval, renewal, deadline and scheduled event across your clients in one list, find the loose ends with no schedule, and subscribe to your due dates from your calendar app.

A security program is mostly things that recur: policy reviews, evidence re-checks, vendor reviews, risk reviews, quarterly snapshots. Monitoring puts everything that comes due across your clients in one list, so nothing goes stale quietly. Monitoring is for Foxx Cyber staff; assessors do not have it.

The Monitoring page

Open Monitoring in the sidebar. Four tiles count what is Overdue, Due this week, Due in 30 days (not counting overdue) and the clients with Loose ends; each opens that view. Below them, the list shows what is due at every live client you can see, grouped as Overdue, Due this week, Next 30 days and Later. Filter by:

  • When: overdue only, next 7 days, next 30 days (the default), next 90 days or next year; every window lists overdue items first;
  • What: everything, or one of the kinds below, with how many fall in the window;
  • Client.

Each item links to the record it comes from, with its kind under the title, its client, its owner and how many days away or overdue it is. The list pages at 50 items; a group cut at the end of a page says how many are on this page and that the rest are on the next, where it carries on marked "continued".

What it tracks

KindComes due when
ScheduledAn event on a client's calendar, from today on. A repeating event shows its next occurrence.
Policy reviewA policy, standard, procedure, plan or guideline in effect reaches its next review date.
Evidence re-checkAn evidence item in effect reaches its next review date.
Awaiting approvalA version is still in review two weeks after it was last updated.
Vendor reviewA live vendor on a review cycle reaches its next review date, or has never been reviewed.
Contract endsA live vendor's contract end date.
Risk reviewA risk that is not closed reaches its review date.
Roadmap dueAn open roadmap item's due date.
Appetite re-approvalThe risk appetite's approval date plus its review cycle.
Posture snapshotAbout a quarter (91 days) after an adopted framework's last snapshot, or after it was adopted, for active and onboarding clients.
Program reviewThe client's next program review date, from the profile.
Agreement renewalAn engagement agreement's renewal check.

Archived clients are left out. The portfolio shows the first 25 items of the same list for the next 30 days, overdue first.

Loose ends

Some things never come due because they have no schedule at all. Loose ends lists, per active or onboarding client:

  • program documents with no review cycle;
  • program documents still needed (no version yet);
  • live vendors with no review cycle;
  • open risks with no review date.

Clearing loose ends is what makes the due list trustworthy: once every document, vendor and risk has a schedule, Monitoring shows everything.

Dates follow the practice's time zone

Bedrock GRC works out "today" in your practice's time zone, which is set for the whole deployment. An item moves from "due" to "overdue" at midnight there. Timed calendar events keep their own time and zone.

Your calendar feed

Each person on the staff can turn on a personal calendar feed: an iCalendar (.ics) address that puts the same dates as the Monitoring page into Outlook, Google Calendar or Apple Calendar, and keeps them up to date.

Turn it on

  1. Open Monitoring and find Calendar feed.
  2. Choose Create calendar feed.
  3. Copy the address with Copy address. It is shown only once: Bedrock GRC keeps a keyed hash of it, not the address itself.
  4. In your calendar app, subscribe to a calendar by URL (sometimes called "Subscribe from web", "From URL" or "Internet calendar") and paste the address.

What's in it

  • Every item from Monitoring at the clients you can see, from anything already overdue to a year ahead.
  • Due dates are all-day events titled with the kind, the item and the client, for example "Vendor review: Acme Payroll (Acme Manufacturing)". Items already past due stay on their due date and are titled "Overdue …".
  • Calendar events with a time carry their exact time, so your calendar app shows them in your own zone. Repeating events repeat, and windows span their days.
  • The description has the reference, the client, the owner, any time, joining details and place, and a link back to the record in Bedrock GRC.
  • Events are marked as free time, so they don't block your availability.
  • Each item keeps the same event as its date moves, so a rescheduled review moves in your calendar rather than appearing twice.

The feed asks calendar apps to refresh every six hours. How often they actually do is up to the app.

Keep the address to yourself

The feed address works without signing in, and it shows client names and item titles. Treat it like a password:

  • Don't share it or paste it into a shared calendar.
  • Replace address issues a new one and stops the old one at once; calendars using the old address stop updating.
  • Turn off stops the feed entirely.
  • If an admin disables your account, your feed stops working too.

Last updated October 9, 2026