Assigning a Firm
For Foxx Cyber admins: add a partner assessment firm and its assessors, assign them to a client, hand a framework to the firm, set its branding, and take the framework back.
An outside assessment runs on one client and one framework at a time. An admin sets it up in five steps; after that the firm's assessors work on their own.
1. Add the firm
Open Team and, under Assessment firms, type the firm's name under New firm and choose Add firm. A firm's name must be unique.
2. Add the firm's assessors
Still on Team, under Invite by email, enter the assessor's email (and, optionally, name), pick the role Assessor (outside firm) and the Firm, and choose Send invitation. The role only appears once a firm exists. The assessor gets a one-time link, valid for 7 days, where they choose their own password. When email is not an option, use Add a person with a temporary password instead and share the password directly; they choose their own at first sign-in. See Team and Roles.
An assessor must set up two-step sign-in before they can open anything, and sees no client until you assign them to one. If the firm signs in through its own identity provider, set that up too; see Single Sign-On.
3. Assign them to the client
Open the client's Profile. Under People on this client, pick the assessor under Person, choose Assessor under Role on this client, and choose Add person. They now see the client in their list.
4. Hand the framework to the firm
Open the client's Frameworks tab and the framework row's menu (the button with three dots). Pick the firm under Assessed by and choose Save who assesses it. You can only pick a firm that has an assessor assigned to this client. The row then shows "Assessed by firm" and a phase.
From then on, while the firm holds the framework:
- Only that firm's assessors can change its answers. Foxx Cyber staff, admins included, read them.
- The framework keeps its shape: nobody, admins included, can remove it, adopt it again, change its baseline, or move it to or from NIST SP 800-171 Rev. 3. The Rev. 3 page shows a read-only comparison.
- Crosswalk fills, spreadsheet imports and eMASS imports leave those answers alone: the held rows are skipped and the rest of the import applies.
- The crosswalk never reads the held framework's answers into any other framework.
- The client portal and the board report name the framework as being assessed by the firm and show none of its live answers.
To take the framework back, pick practice staff (for example "Foxx Cyber LLC staff") under Assessed by and choose Save who assesses it. You can always do this, even when the firm no longer has an assessor on the client: the firm then shows as "firm (no assessor left)". Taking it back is recorded in the audit log and leaves every issued version as it was.
5. Set the firm's branding
Open Branding (or the firm's Branding link under Assessment firms on Team), switch to the firm with the picker at the top, and set its name, tagline, logo, colours, contact line and the Assessment reports disclaimer. These go on the assessment reports the firm issues; nothing here changes Foxx Cyber's own board report, portal or emails. See Branding.
Account rules
- A staff account can't become an assessor, or the reverse. If someone moves between Foxx Cyber and a firm, add a new account.
- An assessor is added to a client as Assessor; staff are added as Lead or Support.
- To stop an assessor's access to one client, choose Remove from this client in their row's menu under People on this client. The confirmation reminds you that frameworks their firm is assessing stay with the firm until you hand them back.
- When an assessor leaves their firm, choose Offboard… in their row's menu on the Team page: the account is disabled, their sessions end and they leave every client at once. Their firm keeps the frameworks it holds, and every version they issued stays as it was. See Team and Roles.
- Archiving a client closes it to assessors until it is restored.
- When two firms work on the same client, each sees only its own issued versions and its own framework's calendar events.
- A restored backup never re-adds an assessor. The restore (an admin action) says which assessors were left out; assign them again on purpose. A held framework stays held after a restore only if a firm with the same name exists here.
What staff do while the firm works
Staff keep working the rest of the client's program as usual. On the held framework they can read every answer, see the phase move from Planning to Assessing, and open Issued assessments once the firm issues. From each finding in an issued version, Plan this starts a roadmap item. See Issuing an Assessment.