Secure · Enforce · Train
Portal User Flows
Admin Portal sold to MSSPs
Overview
Dashboard
The MSSP's home screen — a one-look summary of the whole book of business across every client.
See headline counts (total clients, systems, submitted policy documents, final reports), spot clients needing attention, and jump into common tasks.
They land here after login. If clients uploaded documents awaiting review, an orange banner appears — they click it to jump to the review screen.
Counts and charts are pulled together live across all clients; clicking a Quick Action or the banner opens the relevant screen.
Analytics
Shows whether clients are responding to what they're sent, and how quickly.
Pick a time window and review questionnaire activity — total responses, completion rate, average completion time — per day, per questionnaire, per client.
They choose a date range; charts and numbers update to that window.
The platform tallies activity in the window and draws trend charts, surfacing stalled clients or weak questionnaires.
Activity Log
A searchable feed of actions taken in the platform, tagged with who did it and which client it relates to.
Browse newest activity, filter by user type (admin vs. customer) or client, and search by user, action, or detail.
They scroll or use the search box / filters; each row shows time, person, action, detail, and client.
Matching entries appear instantly. (Target build: every change recorded, making this a complete audit trail.)
Clients & Org
Clients
The master list of every client organization the MSSP serves, and where each client's portal access ("license") is switched on or off.
Add, edit, delete, and re-order clients; search by name/email/industry; toggle portal access; open a client to manage deeper settings including their vendors.
They click "Add Client" and fill a short form; flip the access toggle on a card; drag cards to reprioritize.
New clients start with access ON. Any client older than one year auto-switches to "no access," showing them an "Annual License Expired" screen until renewed — the renewal lever.
Org Structure Admin
Builds and maintains a client's org chart — departments, roles, addresses — feeding training scope, supply-chain mapping, and policy context.
Pick a client and edit organization details: name, address, departments, and roles (each tagged in-house / contractor / outsourced).
They select the client and type into the fields, adding departments/roles.
Edits save automatically; the structure becomes available to workflows that rely on it.
Questionnaires
List Questionnaire
Manages standard question-and-answer questionnaires — the library of templates and the copies assigned to clients.
Create by hand or by uploading a file, edit/delete, and assign a template to a client.
They switch between "templates" and "assigned" tabs, use the builder/uploader, and click "assign."
An assigned questionnaire appears in that client's portal; answers come back under Responses.
Table Questionnaire
Questionnaires where the client fills in a table — each row a system, asset, vendor, or process. This data becomes the inventory Systems Analysis and BCP build on.
Create a table by defining columns, or import from a spreadsheet (columns mapped automatically); preview, edit, delete, assign.
"Create New Table" to define columns, or "Create from CSV" and upload; then assign to a client.
The client fills the rows; those rows become the system/process inventory used downstream.
Questionnaire Generator AI
Writes an entire questionnaire from a plain-language description.
Describe topic, industry, number of questions, complexity, language, question types — and get a complete, ready-to-edit questionnaire.
They fill a short spec form, click generate, and tweak in a preview tab.
The AI produces the full questionnaire as a draft; saving makes it a master template ready to assign.
Writes the complete questionnaire — title, description, and a full set of correctly-typed questions — from the admin's short plain-language spec.
Responses
The inbox where the admin reviews everything clients have submitted.
Read answers and attachments, filter by status, and re-open a submitted response so the client can fix and resubmit.
They open a response to read it; click "restore to draft" to re-open it.
Restoring puts the response back in the client's portal as editable, and they can resubmit.
Compliance & Policies
Standards DB AI
The library of standards/frameworks that powers questionnaires, policy writing, gap analysis, and reports. Each standard can be broken into clauses.
Add a standard, upload its source document, and have the AI extract clauses and generate plain-language explanations plus three "lenses" of requirements (general, IT-systems, supply-chain).
They create the standard, upload the framework document, and trigger extraction.
The AI lists the clauses automatically; those feed the generators, risk mapping, and reports.
Reads the uploaded framework document and extracts its individual clauses, then writes plain-language explanations and the three requirement lenses (general, IT-systems, supply-chain).
Policy Generator AI
Drafts a complete, client-specific policy document end to end, then turns it into a publishable PDF once approved.
Pick a client and template, let the AI write the policy, refine sections by chatting with the AI, and approve.
They select client + template; the platform pulls in org structure, systems, standards; the AI drafts the section list and writes each section; the admin types refinements in a chat; then clicks Approve.
The AI generates annexes and assembles the document. On approval it becomes an Approved Policy the client can view/download; otherwise "needs revision."
Builds the policy's section outline, writes the content of each section, drafts the supporting annexes, assembles the final formatted document, and powers the refinement chat.
Compliance Documents AI
Where the admin reviews policy documents clients uploaded and grades them against the standards.
Open an uploaded document, run an AI analysis against the standards, set a verdict, and produce a consolidated summary across several documents.
They open a client's document (flagged on the Dashboard banner), run the analysis, then set approved / needs revision / rejected.
The AI returns gaps, a score, and recommendations; the verdict and required revisions become visible to the client.
Analyzes each uploaded document against the standards to produce identified gaps, a score, and recommendations — and a consolidated executive summary across multiple documents.
Checklists AI
Turns a standard into a trackable checklist of recurring compliance tasks assigned to a client.
Import items from a standard, assign to a client, and monitor completion.
They pick a standard, let the AI import the items (task, owner, frequency, source clause), then assign.
The client ticks items off with evidence; the admin sees percent-complete, and incomplete items can flow into the Workplan.
Imports the checklist items from the chosen standard — each with a task, a suggested owner, a frequency, and the source clause.
Security & Risk
Compliance Scans AI
Takes uploaded technical security reports and turns them into structured, explained findings with remediation guidance and a client-facing report. Covers general assessments, pen tests, external attack-surface, and code reviews.
Upload a report under a category, review extracted findings, get AI remediation guidance per finding, and compile a report.
They choose a category, upload the file, click into any finding for AI guidance, and optionally add context/evidence.
The AI extracts each finding and writes remediation steps; the report appears in the client's Security area, and findings can seed Workplan tasks.
Extracts the findings (severity, title, evidence) from the uploaded report, writes detailed remediation guidance for each, and compiles the client-facing report.
Cyber Security AI
Manages the client's security tools and their scan results, tracking configuration quality and mitigation over time.
Record tools, upload scan output, get an AI summary and mitigation steps, and move each issue through its lifecycle.
They add a tool, upload output, and work each issue open → in progress → resolved using AI-recommended steps.
The AI parses the scan, writes an executive summary, and summaries surface in the client's portal.
Parses the tool's scan output into structured findings, writes an executive summary, analyzes supporting evidence, and recommends mitigation steps.
Risk Management AI
The risk hub — gathers gaps from across the platform (training, cyber, supply chain, systems, processes) and maps them to NIST 800-53 controls.
Review aggregated gaps mapped to controls and make a risk decision per gap (accept / mitigate / transfer / avoid).
They open the hub (gaps gathered automatically), review the mapping, and pick a decision for each.
The AI maps each gap to controls and produces a gap analysis; "mitigate" decisions generate Workplan tasks.
Maps each gathered gap to specific NIST 800-53 controls and produces the gap analysis.
Files Analysis AI
Scans a client's uploaded documents (Hebrew/English images, PDFs, forms) to identify what kinds of data the organization holds.
Select a file and have the AI identify the data types in it, with new/unexpected types flagged.
They pick a file and run the analysis.
The AI extracts the data types; results roll up into a per-client consolidated data report linked to systems.
Reads the files (including Hebrew/English images, PDFs, and forms) and identifies the data types present, flagging any new or unexpected ones.
Systems & Continuity
Org Systems Analysis AI
Builds a full understanding of each client IT system — what it is, how data flows, how it measures against standards, how risky it is. The system list is derived from table-questionnaire answers.
Pick a system and let the AI analyze it end to end; watch risk scores update as remediation happens.
They select a system from the auto-built list and run the analysis.
The AI draws a data-flow diagram, writes documentation, checks against standards, scores risk, and drops fixes into the Workplan. A "mitigated score" updates as fixes land; results appear in the client's Systems Analysis view.
Draws the system's data-flow diagram, writes its documentation, checks it against the standards (controls met vs. gaps), scores its risk, and emits the recommended remediation tasks.
BCP AI
Builds the client's business-continuity picture — which processes are critical, what downtime costs, and how to recover. Processes derived from table questionnaires.
Review each process's impact analysis, cost exposure, and recovery plan generated by the AI.
They open a client's processes (extracted automatically) and run the BCP analysis.
Per process the AI works out recovery objectives and criticality, estimates downtime cost and annual loss, drafts recovery steps, and draws a flow diagram — surfaced in the client's BCP dashboard.
Runs each process's business-impact analysis (recovery objectives, criticality), estimates downtime cost and annual loss, drafts the recovery steps, and draws the process flow diagram.
Supply Chain
Supply Chain Management AI
Manages a client's third-party/vendor risk — sending vendors questionnaires and document requests, then scoring each vendor's risk.
Assign questionnaires and required documents to vendors, review the AI's risk analysis, and produce a consolidated supply-chain report.
They assign questionnaires/documents to vendors; vendors respond (vendor surface — out of scope); the admin reviews the AI analysis.
The AI scores responses against requirements, reviews documents, sets a risk level per vendor, and assembles a report; the client sees a vendor risk matrix.
Scores each vendor's responses against the requirements, reviews their uploaded documents, sets an overall risk level per vendor, and assembles the consolidated report.
Training
Program AI
Plans and produces the client's security-awareness training — programs per department, generated content and instructor kits, scheduled sessions, and post-training competency scoring.
Define a program, generate content and instructor materials, schedule sessions, issue a public link for employees to answer post-training questions, and review competency.
They define the program (department, modules, topics) and let the AI generate content, kits, scenarios, and a session plan; they schedule sessions and generate a one-time 24-hour public link.
Employees answer via the link without an account; the AI scores competency and produces a progress report; gaps flow into the Risk Management training lane.
Generates the training content per module, builds the instructor kits, creates custom scenarios and a session plan, and scores employee competency into a progress report.
Outputs
Workplans AI
The single place all remediation work converges — every gap found anywhere drops a recommended task here.
Review accumulated and manual tasks, have the AI break complex tasks into sub-steps with effort/cost estimates, assign owners, and track progress.
They pick a client, review the task list, and move tasks draft → approved → in progress → completed; owners update percent-complete.
Tasks are tracked to completion and also surface to the client in their Workplans/Monitoring views.
Breaks complex tasks into sub-steps and estimates the effort and cost for each.
Reports AI
Produces the formal, polished compliance report — the deliverable the client pays for — built section by section and exported as a PDF. Generated in one selected language at a time (Hebrew by default; Hebrew, English, Arabic, Russian, or French), never mixed.
Pick a client and sections to include, let the AI write each section, and produce the final PDF.
They select the client and report sections and trigger generation.
The platform aggregates the client's data; the AI writes each section including a controls-assessment table and a remediation-plan table; the sections compose into a downloadable PDF.
Writes each section of the report (executive summary, methodology, findings, etc.), including the controls-assessment table and the remediation-plan table.
AI Assistant
BNAI Agent AI
A conversational AI assistant the admin can ask compliance questions of, drawing on the platform's knowledge (standards, policies, and the user's organizational context).
Ask questions in a chat and get context-aware answers, with follow-ups remembered.
They type a question into the chat window.
The assistant pulls in relevant context and streams back an answer; the conversation is kept so follow-ups stay on topic.
Retrieves the relevant context (standards, policies, the user's organizational context) and generates the conversational answer.
Customer Portal the MSSP's clients
Domain 1 — Compliance
Compliance Dashboard
The landing overview of compliance health — a headline score plus breakdowns by systems, policies, security risk, and questionnaires.
Read overall Compliance Score and Mitigation Progress, see analyzed/approved counts, review assigned questionnaires with status, and scan the main compliance tasks.
View-only — they open it and scroll the cards and progress bars.
Numbers and bars reflect current data and recalculate as work is completed elsewhere.
Compliance Framework
A consolidated checklist of every outstanding compliance task — pending questionnaires, pending policy submissions, security vulnerabilities, and a systems work-plan table.
See an overall percent-complete bar, expand each category, click a system row to open its gaps and tick them off, and translate a section to Hebrew.
They expand a category, and for systems click a row to open a "gaps found" pop-up where they check off each gap.
Checking gaps updates that system's mitigation status and projected score; bars move. Most rows link back to where the work is actually done.
Organization Systems (Questionnaires) primary client input
The questionnaire workspace — the main place the client provides information. Lists assigned questionnaires with status.
Start a pending questionnaire, continue a draft, preview questions, view/re-edit a submitted response, and upload/manage organization files.
They click Start/Continue, answer each question (text, choices, tables, attachments) — work auto-saves — and click Submit; documents go through the upload buttons.
Submitting marks it Completed and feeds answers into the platform — table questionnaires auto-populate the "systems" list used by Systems Analysis, Data Flow, BCP, and more. A confirmation shows and counters update.
Organizational Structure client input
A form describing the organization: basic details, departments, and roles per department.
Review auto-filled details, edit them, add/remove departments and roles, add/remove organizations, upload an org-chart file, and download the structure.
They expand sections, type into fields, and use Add/Remove buttons; changes save automatically.
The saved structure becomes the backbone for training programs, BCP impact analysis, process costing, and monitoring.
Policies & Procedures (Required Documents) client input
Lists the policy documents the client must submit, grouped by set, each with a status (Pending → Submitted → Under Review → Approved/Needs Revision/Rejected).
Read guidelines, upload the required document (or a revision), view their submission, withdraw one under review, delete a rejected one, read admin feedback, and open the finalized policy for approved items.
They click "Upload Document," pick a file (PDF/CSV/PNG/JPG), and confirm; click the Feedback badge to read notes; click "View Policy" to open the finished document.
Uploading sets it to Submitted and sends it for MSSP review; withdrawing/deleting resets to pending. Status badges and the dashboard update.
Document Analysis
A read-only view of how submitted policy documents were assessed — statuses, scores, analysis, and annex documents.
Browse documents, see approval status and scores, open analysis details, and view annexes.
They scroll the list and click a document to expand its analysis.
The analysis is displayed for reading; uploading happens in Policies & Procedures.
Org. Standard Framework
Lets the client browse the requirements (clauses and annexes) of standards relevant to them.
Tick standards to view, see clauses/annexes as cards, and click a clause to open its implementation guide.
They check a standard's box; requirements load; they click a clause to read guidance.
Their selection is remembered. Reference material; if an admin hasn't generated requirements yet, it shows an empty state.
Systems Analysis
Shows each system (from table questionnaires) as a card with its AI compliance analysis, score, risk level, and data classification.
Browse cards, open a system's full analysis, translate it to Hebrew, and generate/open a printable report.
They click a card to open the analysis, then use translate and print buttons.
The analysis opens for reading; the report opens in a printable window. Un-analyzed systems point the client to their administrator.
Data flow & Data classification
Per-system view of data handling — data types, hosting, database classification, security level, and data-flow detail.
Browse systems, open a data-detail form, view/generate data-flow diagrams and required-security-document reports, and view classification.
They click a system to open its form, fill/confirm fields, and use report buttons (with a language choice); reports open in pop-ups.
Saved details feed the system's classification and the Final Report; generated reports are stored and reopenable.
Final Report
The consolidated final compliance report, organized into standard sections (cover, executive summary, legal basis, methodology, findings, remediation plan, management decisions, appendices).
See which sections exist, open the full report, open the management-decisions and systems-risk summaries, and print.
They click "View Full Report" (and the management/risk buttons), then print.
The finished report is presented for reading/printing; the client consumes the MSSP's output here.
Domain 2 — Security
Main Dashboard
A visual summary of security posture across all testing types, with risk scores, severity breakdowns, and charts.
Read overall and per-method risk scores, view charts, and jump to a method's detail tab.
View-only; read the cards/charts and click through.
Charts reflect the latest uploaded findings; links open the matching sub-tab.
Security Tools
Shows the security tooling assessed for the client, grouped by segment (endpoint, network, identity, cloud), with findings and risk scoring.
Browse tools by segment, open a finding to read its details, and see risk scores and coverage charts.
They scroll/select tools and click a finding to open its detail dialog.
Finding details and risk visuals are displayed; acting on findings happens in Workplans.
Penetration Testing / External Surface Attack / Security Assessment / Code Review
Four report viewers (same design) presenting findings from each type of engagement the MSSP performed.
Open each uploaded report, read its executive summary, findings with severities, and average risk score, and view evidence images.
They click a file to open its analysis; click a finding/image to enlarge.
The selected report's findings are shown for reading. View-only — the client doesn't upload test files here.
Reports Planned — not yet built
Intended purpose: a consolidated security report for the client. Currently a placeholder.
Workplans interactive
The remediation workspace for security findings — track and prove progress on fixing each finding, per method or per tool.
Pick a method (or tools), pick a file/tool, mark remediation steps done per finding, add comments, and upload evidence.
They select a method, choose a file/tool, open a finding, tick its steps, type notes, attach evidence, and Save (also auto-saves).
Progress is stored against each finding and reflected in the Security dashboard and Monitoring rollups.
Domain 3 — Supply Chain
Main Dashboard
Overview of vendor/supply-chain risk — vendor counts, risk distribution, summary charts.
Read vendor risk tags, counts, and charts; navigate to a sub-tab.
View-only.
Charts reflect the current vendor list and analyses.
Vendor Management client input
The client's vendor register.
Add, edit, and delete vendors (services, contacts, type, risk, compliance status, contract dates, notes); search; copy a vendor-portal link; bulk-import from CSV (one authorized account).
They click Add/Edit to open a form, fill it, and save; use the search box; click delete to remove.
Saved vendors populate every other Supply Chain tab; a copyable link lets vendors fill questionnaires.
Vendors Questionnaires
Shows, per vendor, which questionnaires were assigned and their response status.
Pick a vendor to see its questionnaires; open a submitted response to view it.
They click a vendor to expand its questionnaires, then click one to open the viewer.
The vendor's response is displayed read-only (vendors fill these via the separate vendor link).
Vendor Files
Browse files attached by vendors, with optional AI analysis of a file.
Choose a vendor, then a questionnaire or document, then a file; view it; trigger/read an AI analysis.
They drill vendor → source → file via dropdowns, then view or analyze.
The file opens; analysis results are shown/stored for that file.
Systems & Services client input
Maps which of the organization's systems each vendor supports, with service-criticality and SLA details.
Assign systems/services to vendors, set severity (critical/moderate/basic) and SLA expectations, and save.
They select systems, set the fields, and click Save.
These vendor-to-system links feed the supply-chain risk view, BCP, and the SCRM policy.
Risk Assessment AI
Assesses each vendor against a chosen standard, producing per-vendor gap analyses and scores.
Choose a standard, run/view AI risk analysis per vendor, open a vendor's detail panel, and view requirements.
They pick a standard; saved analyses load and each vendor's panel can be opened.
Per-vendor scores, risk levels, and gaps are displayed/saved and roll up into Compliance Tracking and the Final Report.
Analyzes each vendor against the chosen standard, producing per-vendor gap analyses and risk scores.
Compliance Tracking
A consolidated view of every vendor's compliance status — scores, risk levels, and the systems each vendor touches.
Expand each vendor to see standards analyzed, scores, risks, and linked systems.
View-only; click to expand a vendor.
Displays the aggregated vendor compliance picture for reading.
Final Report
A consolidated supply-chain report bringing together vendors, gap analyses, system links, scores, and risks.
Read the assembled report and download it.
They open the tab and use the download button.
The finished report is presented/downloaded.
SCRM Policy AI
Generates and stores a Supply Chain Risk Management policy tailored to the client's actual vendor ecosystem.
Generate the policy, read it, regenerate it, save it, and download it.
They click Generate; the system drafts it from their vendor data; they review and Save/Download.
The generated policy is stored and can be reopened, regenerated, or downloaded later.
Drafts the Supply Chain Risk Management policy from the client's actual vendor data.
Domain 4 — Training
Main Dashboard
Overview of training posture — average scores by department and standard, with charts.
Read score bands, per-department and per-standard averages, and summary charts.
View-only.
Charts reflect programs, sessions, kits, and employee questionnaire submissions on file.
Training Programs AI
Builds/views training requirements and per-department programs for a chosen standard.
Pick a standard, generate or view requirements, generate per-department programs, and open a department's program detail.
They select a standard, click to generate, and open a department to view its program.
Generated requirements/programs are saved and become the basis for kits and the annual plan.
Generates the training requirements and the per-department programs from the chosen standard.
Training Kits
A library of instructor/training kits, organized by department and standard.
Browse kits by department then standard and open a kit to view its contents.
They drill department → standard → kit and click to open the viewer.
The selected kit opens for viewing.
Annual Training Plan
A month-by-month schedule matrix of training modules across a two-year horizon.
View the schedule grid and open a kit/module from the matrix.
They read the matrix and click a scheduled module to open it.
Shows the planned training calendar; opening a module shows its kit.
Training Questionnaires
The training/awareness questionnaires (employee Q&A) available to present or review.
Browse questionnaires and open the employee Q&A presenter to run/review them.
They click a questionnaire to open the presenter.
The questionnaire content is presented for delivery/review.
Submitted Questionnaires
Shows employees' submitted training questionnaires with scoring and analysis.
Browse submissions, view score bands and averages, and open an individual submission's analysis.
They scroll the list/charts and click a submission to view details.
Submission scores and analysis are displayed and roll into the training dashboard.
Policy Evaluation Planned — not yet built
Intended purpose: evaluate training against policy requirements. Currently a placeholder.
Detail Analysis Planned — not yet built
Intended purpose: deeper per-employee/per-topic training analysis. Currently a placeholder.
Domain 5 — BCP (Business Continuity)
Main Dashboard
A readiness overview for business continuity — incident-response readiness, business-impact coverage, and remediation progress.
Read continuity-readiness scores and risk labels and navigate to sub-tabs.
View-only.
Scores reflect current system risk and continuity data.
Process Map AI
Maps the organization's operational processes to departments (AI-assisted, Hebrew/English aware).
View processes grouped by department, auto-classify processes into departments, review priorities, and open process detail.
They trigger AI classification and review/adjust the mapping.
The mapping is saved and feeds Business Impact Analysis, Process Cost, and Monitoring.
Classifies the organization's processes into the right departments (Hebrew/English aware).
Process Data Flow AI
Per-process detail showing which systems and vendors each process depends on, with flow diagrams.
Expand processes, assign systems (manually or via an AI bulk generator), generate flow diagrams, set owners, and view summaries.
They expand a process, pick systems, run the generators, and open diagrams.
Assignments and diagrams are saved per process and feed BIA, costing, and continuity planning.
Bulk-generates the system dependencies for each process and draws the process-flow diagrams.
Process Cost AI
Calculates the cost of running each process (people, systems, vendors, overhead) and compares manual vs. AI/automated cost.
Enter cost inputs per process, use AI estimators to auto-fill, save, view a summary, and generate a cost report.
They fill the fields (or run the AI estimators), then Save; they open the summary and report.
Saved cost data drives the savings figures in the Monitoring dashboard and the cost report; totals recompute live.
Estimates the cost inputs and auto-fills the costing fields.
Business Impact Analysis
A full BIA table per process (recovery objectives, maximum tolerable downtime, operational/financial/legal/reputational impacts, recovery priorities, minimum resources, criticality).
Pick a department, view its processes' BIA records, and open a formatted BIA viewer.
They select a department, load its processes, and open the BIA view.
The detailed BIA is displayed for reading and feeds continuity readiness.
Business Continuity Plan · Org. Risk Management · Data Recovery Plan · Workplan · Reports Planned — not yet built
Intended purpose: the planning/output half of BCP — the assembled continuity plan, org-level risk register, data backup/recovery procedures, continuity remediation tasks, and continuity reports. All five are currently placeholders. (The data-gathering half above is built.)
Domain 6 — Monitoring
Main Dashboard
An operational/financial monitoring overview by department — process counts, automation status, and projected savings (manual vs. AI cost).
Read per-department process counts, savings figures, and an automation pie chart; open a department to see its processes.
View-only with a click-to-expand department view.
Figures are computed from the process map and saved process-cost data.
Workplans Management
A roll-up of remediation progress across the security methods, showing percent-complete per workplan.
Select a method and read progress cards (done/total, percent complete) per area.
View-mostly; they pick a method and read the bars.
Progress reflects the remediation tracked in Security → Workplans.
Compliance Analysis · Security Analysis · Training Analysis · Business Processes Planned — not yet built
Intended purpose: cross-cutting trend analyses per domain. All four are currently placeholders.
Cross-Portal Flows Admin ↔ Customer
Status & Placeholders
Both portals are documented at full per-tab depth. The only items not described in full behavior are genuine placeholders in the current code:
Still placeholders (planned, not yet built):
- Security → Reports
- Training → Policy Evaluation, Detail Analysis
- BCP → Business Continuity Plan, Org. Risk Management, Data Recovery Plan, Workplan, Reports
- Monitoring → Compliance Analysis, Security Analysis, Training Analysis, Business Processes
Everything else listed is built and functional in the current MVP. This report is the review copy; once approved it becomes the closing user-flow section of the formal specification document.