Skip to content
Foxx Cyberfoxxcyber/docs

Finding Your Way Around

A tour of Bedrock GRC's navigation for staff and for assessors: the sidebar, a client's header and tabs, and the reference numbers used across registers.

Bedrock GRC has two levels: the practice (everything across your clients) and the client (one security program). The sidebar takes you around the practice; a client's tabs take you around its program. What you see depends on whether you are Foxx Cyber staff or an assessor from a partner firm.

The sidebar

ItemWhat it isWho sees it
PortfolioThe home page: every live client you can see, what needs attention first, and everything due in the next 30 days.Staff
ClientsThe client list, with Archived clients for former engagements. New client starts a record; admins can also restore one from a backup there.Everyone (assessors see only their assigned live clients, and viewers cannot create clients)
MonitoringEverything that comes due across your clients, loose ends with no schedule, and your calendar feed.Staff
FrameworksThe shared reference catalog, with each framework's description, source and a download of the catalog with its crosswalks.Everyone
Team, Audit log, Branding, Single sign-onUnder Practice.Admins
AccountUnder You: your display name, password, two-step sign-in, single sign-on link and signed-in sessions.Everyone
DocumentationOpens this documentation in a new tab.Everyone

The top bar holds the search box, which finds clients and records across every live client you work on (see Search), and the theme button, which switches between light and dark. Assessors have no search box. Your name, role (and, for an assessor, firm) and Sign out are at the foot of the sidebar.

Inside a client

Every client page opens with the client's header: name, industry and size, status, service tier, CMMC target, and chips for DIB, Handles CUI and the next program review date. Assessors from a partner firm do not see the status, service tier or review date. For staff, three buttons sit on the right:

  • Client access: read-only portal links and emailing the board report. See The Client Portal.
  • Import / export: workbooks, CSVs, bulk file upload and the full backup. See Import and Export.
  • Board report: opens the executive report as a page of its own. See The Board Report.

Staff tabs

TabWhat lives there
OverviewHeadline numbers, what is next on the calendar, first steps for a new client, framework posture, top risks, the next 90 days of roadmap work, the heat map, goals, key vendors, crown jewels, recent engagement, the client's contacts and the team on the client.
StrategyBusiness goals and the risk appetite.
RisksThe risk register and heat maps.
AssetsThe asset register.
VendorsThe third-party register.
FrameworksAdopted frameworks, posture, snapshots and trend lines. Each framework opens into its control-by-control assessment.
RoadmapThe remediation plan (POA&M).
DocumentsPolicies, standards, procedures, plans and guidelines.
EvidenceProof that controls operate.
CalendarWhat is planned with the client.
EngagementFoxx Cyber's agreements with the client, the engagement log and the client's audit trail.
ProfileWho the client is, their contacts, the people on the client, and archiving.

Assessor tabs

An assessor opens a client on its Frameworks tab and has seven tabs: Frameworks, Evidence, Documents (the program documents in effect, read only), Strategy, Assets, Vendors and Calendar. The header buttons (Client access, Import / export, Board report) are not shown. What an assessor can do on each tab is on Working as an Assessor.

Reference numbers

Records get a per-client reference number that never changes and that imports use to match rows:

PrefixRecord
R-001Risk
RM-001Roadmap item
DOC-001Document, evidence item or agreement
V-001Vendor
A-001Asset

Who sees what

  • Admins see every client, archived ones included, and change every live one.
  • Consultants see only the clients they are on. On each one, an admin sets whether they edit or only read it. A consultant who creates a client is put on it as the lead, with edit access.
  • Viewers see only the clients they are on, and change nothing.
  • Assessors see only the live clients they are on, and there only the areas listed above.

Any other client behaves as if it does not exist. When you only read a client, its pages show no forms or buttons that would change it. An archived client is read-only for everyone, admins included, until it is restored (an admin can also delete it permanently), and assessors no longer see it. See Team and Roles.

Forms and messages

Bedrock GRC checks a form before it is sent and again on the server:

  • A field that needs fixing is marked, with a message under it saying what to change. Fix it and send the form again.
  • When the server refuses a form, the page comes back with what you typed still in it, a message under each field to fix, and a note at the top saying how many fields are marked. Passwords, secrets and two-step codes are never filled back in.
  • A message from the server stays until you edit that field, so typing elsewhere does not clear it.
  • Reloading the page after a refused form shows the page again; it never sends the form a second time.
  • Confirmations, warnings and hints appear inside the page, never as browser pop-ups.

A refusal that is not about one field, such as a lockout or a change someone else made first, shows as an alert at the top of the page. A refusal never looks like the confirmation that a change was saved.

Last updated October 9, 2026