Finding Your Way Around
A tour of Bedrock GRC's navigation for staff and for assessors: the sidebar, a client's header and tabs, and the reference numbers used across registers.
Bedrock GRC has two levels: the practice (everything across your clients) and the client (one security program). The sidebar takes you around the practice; a client's tabs take you around its program. What you see depends on whether you are Foxx Cyber staff or an assessor from a partner firm.
The sidebar
| Item | What it is | Who sees it |
|---|---|---|
| Portfolio | The home page: every live client you can see, what needs attention first, and everything due in the next 30 days. | Staff |
| Clients | The client list, with Archived clients for former engagements. New client starts a record; admins can also restore one from a backup there. | Everyone (assessors see only their assigned live clients, and viewers cannot create clients) |
| Monitoring | Everything that comes due across your clients, loose ends with no schedule, and your calendar feed. | Staff |
| Frameworks | The shared reference catalog, with each framework's description, source and a download of the catalog with its crosswalks. | Everyone |
| Team, Audit log, Branding, Single sign-on | Under Practice. | Admins |
| Account | Under You: your display name, password, two-step sign-in, single sign-on link and signed-in sessions. | Everyone |
| Documentation | Opens this documentation in a new tab. | Everyone |
The top bar holds the search box, which finds clients and records across every live client you work on (see Search), and the theme button, which switches between light and dark. Assessors have no search box. Your name, role (and, for an assessor, firm) and Sign out are at the foot of the sidebar.
Inside a client
Every client page opens with the client's header: name, industry and size, status, service tier, CMMC target, and chips for DIB, Handles CUI and the next program review date. Assessors from a partner firm do not see the status, service tier or review date. For staff, three buttons sit on the right:
- Client access: read-only portal links and emailing the board report. See The Client Portal.
- Import / export: workbooks, CSVs, bulk file upload and the full backup. See Import and Export.
- Board report: opens the executive report as a page of its own. See The Board Report.
Staff tabs
| Tab | What lives there |
|---|---|
| Overview | Headline numbers, what is next on the calendar, first steps for a new client, framework posture, top risks, the next 90 days of roadmap work, the heat map, goals, key vendors, crown jewels, recent engagement, the client's contacts and the team on the client. |
| Strategy | Business goals and the risk appetite. |
| Risks | The risk register and heat maps. |
| Assets | The asset register. |
| Vendors | The third-party register. |
| Frameworks | Adopted frameworks, posture, snapshots and trend lines. Each framework opens into its control-by-control assessment. |
| Roadmap | The remediation plan (POA&M). |
| Documents | Policies, standards, procedures, plans and guidelines. |
| Evidence | Proof that controls operate. |
| Calendar | What is planned with the client. |
| Engagement | Foxx Cyber's agreements with the client, the engagement log and the client's audit trail. |
| Profile | Who the client is, their contacts, the people on the client, and archiving. |
Assessor tabs
An assessor opens a client on its Frameworks tab and has seven tabs: Frameworks, Evidence, Documents (the program documents in effect, read only), Strategy, Assets, Vendors and Calendar. The header buttons (Client access, Import / export, Board report) are not shown. What an assessor can do on each tab is on Working as an Assessor.
Reference numbers
Records get a per-client reference number that never changes and that imports use to match rows:
| Prefix | Record |
|---|---|
R-001 | Risk |
RM-001 | Roadmap item |
DOC-001 | Document, evidence item or agreement |
V-001 | Vendor |
A-001 | Asset |
Who sees what
- Admins see every client, archived ones included, and change every live one.
- Consultants see only the clients they are on. On each one, an admin sets whether they edit or only read it. A consultant who creates a client is put on it as the lead, with edit access.
- Viewers see only the clients they are on, and change nothing.
- Assessors see only the live clients they are on, and there only the areas listed above.
Any other client behaves as if it does not exist. When you only read a client, its pages show no forms or buttons that would change it. An archived client is read-only for everyone, admins included, until it is restored (an admin can also delete it permanently), and assessors no longer see it. See Team and Roles.
Forms and messages
Bedrock GRC checks a form before it is sent and again on the server:
- A field that needs fixing is marked, with a message under it saying what to change. Fix it and send the form again.
- When the server refuses a form, the page comes back with what you typed still in it, a message under each field to fix, and a note at the top saying how many fields are marked. Passwords, secrets and two-step codes are never filled back in.
- A message from the server stays until you edit that field, so typing elsewhere does not clear it.
- Reloading the page after a refused form shows the page again; it never sends the form a second time.
- Confirmations, warnings and hints appear inside the page, never as browser pop-ups.
A refusal that is not about one field, such as a lockout or a change someone else made first, shows as an alert at the top of the page. A refusal never looks like the confirmation that a change was saved.