Working as an Assessor
For assessors from a partner firm: what you can open and change in Bedrock GRC, how to assess a framework your firm has been given, and how your work is recorded.
Partner assessment firms work in Bedrock GRC by arrangement with Foxx Cyber. As an assessor you work inside the records of the clients you are assigned to: you assess the frameworks your firm has been given, manage the evidence, and issue the result as a frozen, versioned assessment in your firm's name. Foxx Cyber staff read your answers and plan remediation from them, but cannot change them.
Signing in
A Foxx Cyber admin creates your account under your firm. Usually you get an invitation email: choose Accept the invitation, choose your password, and you are signed in. The link works once and expires after 7 days. If instead you were given a temporary password, sign in with it and choose your own password first. See Your Account and First Sign-In.
Then set up two-step sign-in. It is always required for assessor accounts, whatever Foxx Cyber's own team policy is, and you are sent to set it up before you can open anything else. You can't turn it off. See Two-Step Sign-In.
If your firm has set up single sign-on with its own identity provider, link your account from Account → Single sign-on and sign in that way from then on. You still need two-step sign-in here, unless your firm trusts the provider's multi-factor sign-in and the provider reports it. See Single Sign-On.
You land on Clients, which lists only the live clients you are assigned to. A client appears there once an admin assigns you to it; until then the list is empty. A client that is archived disappears from your list until it is restored.
Your sessions end after a period without activity and a fixed time after sign-in, as for everyone; see Sessions.
What you can open
On each client you are assigned to:
| Area | What you can do |
|---|---|
| Frameworks your firm holds | Read and answer every control: status, current and target maturity, narrative, evidence location, and objectives one by one. Issue the assessment. Frameworks your firm does not hold are not listed. |
| Evidence | Read the practice's evidence and your firm's. Add evidence; on your firm's evidence, and on the practice's while it is linked to a framework your firm holds, edit its details, start new versions, attach files, link it to controls of your firm's frameworks, and send a version for review. Evidence another firm's assessor added does not exist for you, and yours does not exist for them. Links to frameworks your firm does not hold are not shown to you, and your changes never remove them. |
| Documents | Read the client's program documents (policies, standards, procedures, plans) that have a version in effect, as that version and its files. Never drafts, documents still needed or retired, or history. |
| Strategy | Read the business goals and risk appetite, for context. |
| Assets and Vendors | Read the registers, for context, without the risks and contracts linked to them, contract dates or the practice's internal notes. |
| Calendar | Read the client's events that are not tied to a framework (without the practice's notes on them), and the events of the frameworks your firm holds. Add, edit and remove the events of your firm's frameworks, such as interviews and the on-site week. |
Everything else does not exist for you: the portfolio, Monitoring, search, other clients, archived clients, risks, the roadmap, the engagement log, client access links, the board report, exports, imports and backups. Opening one of those addresses shows "not found", the same as a page that doesn't exist.
Foxx Cyber staff accept, return, retire and delete evidence; you can never mark evidence as accepted, including when you add it. Once you send an evidence version for review, a staff member takes it from there.
The Documents tab is a read-only library: it lists only the program documents in effect, with a filter by Every document in effect or Review due or overdue, type and title, and each document opens on its version in effect. At the top of the Evidence and Documents tabs, the Evidence and Program documents · read only chips switch between the two. A document that is only a draft, still needed or retired does not exist for you, even by its address.
Assess a framework
Open a client and its Frameworks tab. It lists the frameworks your firm holds, with their posture and phase. Choose Assess, then work through the controls as described in Assessing Controls:
- Answer each control, or each of its objectives one by one where the framework has them.
- Not applicable needs a reason. Say in the narrative why the control does not apply. Without one, the control blocks issuing.
- Put the proof in the Evidence library and link it to the control; use the control's Evidence field to say where the proof lives.
- Save and next moves through the framework in order. On a control page, Ctrl+Enter saves (and opens the next control), and J and K move between controls. Moving to another control while your changes are not saved shows a note first; moving again leaves without saving.
The control page's Crosswalk panel shows only frameworks your firm holds, and Documents and evidence shows only evidence.
When another partner firm also works on the same client, you never see its frameworks, its issued versions or its framework events, and it never sees yours.
Issue the assessment
When every in-scope control has your firm's answer, issue the assessment from Issued assessments on the framework page. See Issuing an Assessment.
How your work is recorded
- Every change you make is in the client's audit trail and the practice audit log with your name and your firm's name.
- Each answer records who saved it and when. Issuing checks that every answer in scope was last saved by someone from your firm.
- Document history entries for your actions read "Your name (Firm)".
- When you issue, the version records you, your firm and the time, and can never be edited or deleted.
Your client relationship
Bedrock GRC gives your firm a place to work inside a client's record that Foxx Cyber hosts. What you are engaged to assess, and what you share with whom, is agreed between your firm, the client and Foxx Cyber, not by the software. Issued assessment reports are not shown in the client portal.