Secure · Enforce · Train

Portal User Flows

How the two portals relate. The Admin portal is sold to MSSPs — their analysts run compliance & security work for many client organizations, heavily AI-assisted (the admin reviews and approves). The Customer portal is used by the MSSP's clients; it's mostly read-only, with real inputs limited to filling questionnaires, uploading documents, building org structure, managing vendors, and ticking off remediation.
client input = a screen where the user actually enters/changes data AI = AI does the heavy lifting planned = placeholder, not yet built

Admin Portal sold to MSSPs

Overview

Dashboard

What it does

The MSSP's home screen — a one-look summary of the whole book of business across every client.

What the user can do

See headline counts (total clients, systems, submitted policy documents, final reports), spot clients needing attention, and jump into common tasks.

How they do it

They land here after login. If clients uploaded documents awaiting review, an orange banner appears — they click it to jump to the review screen.

What happens

Counts and charts are pulled together live across all clients; clicking a Quick Action or the banner opens the relevant screen.

Analytics

What it does

Shows whether clients are responding to what they're sent, and how quickly.

What the user can do

Pick a time window and review questionnaire activity — total responses, completion rate, average completion time — per day, per questionnaire, per client.

How they do it

They choose a date range; charts and numbers update to that window.

What happens

The platform tallies activity in the window and draws trend charts, surfacing stalled clients or weak questionnaires.

Activity Log

What it does

A searchable feed of actions taken in the platform, tagged with who did it and which client it relates to.

What the user can do

Browse newest activity, filter by user type (admin vs. customer) or client, and search by user, action, or detail.

How they do it

They scroll or use the search box / filters; each row shows time, person, action, detail, and client.

What happens

Matching entries appear instantly. (Target build: every change recorded, making this a complete audit trail.)

Clients & Org

Clients

What it does

The master list of every client organization the MSSP serves, and where each client's portal access ("license") is switched on or off.

What the user can do

Add, edit, delete, and re-order clients; search by name/email/industry; toggle portal access; open a client to manage deeper settings including their vendors.

How they do it

They click "Add Client" and fill a short form; flip the access toggle on a card; drag cards to reprioritize.

What happens

New clients start with access ON. Any client older than one year auto-switches to "no access," showing them an "Annual License Expired" screen until renewed — the renewal lever.

Org Structure Admin

What it does

Builds and maintains a client's org chart — departments, roles, addresses — feeding training scope, supply-chain mapping, and policy context.

What the user can do

Pick a client and edit organization details: name, address, departments, and roles (each tagged in-house / contractor / outsourced).

How they do it

They select the client and type into the fields, adding departments/roles.

What happens

Edits save automatically; the structure becomes available to workflows that rely on it.

Questionnaires

A questionnaire begins as a reusable master template, is assigned (copied) to a client, who fills in a response.

List Questionnaire

What it does

Manages standard question-and-answer questionnaires — the library of templates and the copies assigned to clients.

What the user can do

Create by hand or by uploading a file, edit/delete, and assign a template to a client.

How they do it

They switch between "templates" and "assigned" tabs, use the builder/uploader, and click "assign."

What happens

An assigned questionnaire appears in that client's portal; answers come back under Responses.

Table Questionnaire

What it does

Questionnaires where the client fills in a table — each row a system, asset, vendor, or process. This data becomes the inventory Systems Analysis and BCP build on.

What the user can do

Create a table by defining columns, or import from a spreadsheet (columns mapped automatically); preview, edit, delete, assign.

How they do it

"Create New Table" to define columns, or "Create from CSV" and upload; then assign to a client.

What happens

The client fills the rows; those rows become the system/process inventory used downstream.

Questionnaire Generator AI

What it does

Writes an entire questionnaire from a plain-language description.

What the user can do

Describe topic, industry, number of questions, complexity, language, question types — and get a complete, ready-to-edit questionnaire.

How they do it

They fill a short spec form, click generate, and tweak in a preview tab.

What happens

The AI produces the full questionnaire as a draft; saving makes it a master template ready to assign.

What the AI does

Writes the complete questionnaire — title, description, and a full set of correctly-typed questions — from the admin's short plain-language spec.

Responses

What it does

The inbox where the admin reviews everything clients have submitted.

What the user can do

Read answers and attachments, filter by status, and re-open a submitted response so the client can fix and resubmit.

How they do it

They open a response to read it; click "restore to draft" to re-open it.

What happens

Restoring puts the response back in the client's portal as editable, and they can resubmit.

Compliance & Policies

Standards DB AI

What it does

The library of standards/frameworks that powers questionnaires, policy writing, gap analysis, and reports. Each standard can be broken into clauses.

What the user can do

Add a standard, upload its source document, and have the AI extract clauses and generate plain-language explanations plus three "lenses" of requirements (general, IT-systems, supply-chain).

How they do it

They create the standard, upload the framework document, and trigger extraction.

What happens

The AI lists the clauses automatically; those feed the generators, risk mapping, and reports.

What the AI does

Reads the uploaded framework document and extracts its individual clauses, then writes plain-language explanations and the three requirement lenses (general, IT-systems, supply-chain).

Policy Generator AI

What it does

Drafts a complete, client-specific policy document end to end, then turns it into a publishable PDF once approved.

What the user can do

Pick a client and template, let the AI write the policy, refine sections by chatting with the AI, and approve.

How they do it

They select client + template; the platform pulls in org structure, systems, standards; the AI drafts the section list and writes each section; the admin types refinements in a chat; then clicks Approve.

What happens

The AI generates annexes and assembles the document. On approval it becomes an Approved Policy the client can view/download; otherwise "needs revision."

What the AI does

Builds the policy's section outline, writes the content of each section, drafts the supporting annexes, assembles the final formatted document, and powers the refinement chat.

Compliance Documents AI

What it does

Where the admin reviews policy documents clients uploaded and grades them against the standards.

What the user can do

Open an uploaded document, run an AI analysis against the standards, set a verdict, and produce a consolidated summary across several documents.

How they do it

They open a client's document (flagged on the Dashboard banner), run the analysis, then set approved / needs revision / rejected.

What happens

The AI returns gaps, a score, and recommendations; the verdict and required revisions become visible to the client.

What the AI does

Analyzes each uploaded document against the standards to produce identified gaps, a score, and recommendations — and a consolidated executive summary across multiple documents.

Checklists AI

What it does

Turns a standard into a trackable checklist of recurring compliance tasks assigned to a client.

What the user can do

Import items from a standard, assign to a client, and monitor completion.

How they do it

They pick a standard, let the AI import the items (task, owner, frequency, source clause), then assign.

What happens

The client ticks items off with evidence; the admin sees percent-complete, and incomplete items can flow into the Workplan.

What the AI does

Imports the checklist items from the chosen standard — each with a task, a suggested owner, a frequency, and the source clause.

Security & Risk

Compliance Scans AI

What it does

Takes uploaded technical security reports and turns them into structured, explained findings with remediation guidance and a client-facing report. Covers general assessments, pen tests, external attack-surface, and code reviews.

What the user can do

Upload a report under a category, review extracted findings, get AI remediation guidance per finding, and compile a report.

How they do it

They choose a category, upload the file, click into any finding for AI guidance, and optionally add context/evidence.

What happens

The AI extracts each finding and writes remediation steps; the report appears in the client's Security area, and findings can seed Workplan tasks.

What the AI does

Extracts the findings (severity, title, evidence) from the uploaded report, writes detailed remediation guidance for each, and compiles the client-facing report.

Cyber Security AI

What it does

Manages the client's security tools and their scan results, tracking configuration quality and mitigation over time.

What the user can do

Record tools, upload scan output, get an AI summary and mitigation steps, and move each issue through its lifecycle.

How they do it

They add a tool, upload output, and work each issue open → in progress → resolved using AI-recommended steps.

What happens

The AI parses the scan, writes an executive summary, and summaries surface in the client's portal.

What the AI does

Parses the tool's scan output into structured findings, writes an executive summary, analyzes supporting evidence, and recommends mitigation steps.

Risk Management AI

What it does

The risk hub — gathers gaps from across the platform (training, cyber, supply chain, systems, processes) and maps them to NIST 800-53 controls.

What the user can do

Review aggregated gaps mapped to controls and make a risk decision per gap (accept / mitigate / transfer / avoid).

How they do it

They open the hub (gaps gathered automatically), review the mapping, and pick a decision for each.

What happens

The AI maps each gap to controls and produces a gap analysis; "mitigate" decisions generate Workplan tasks.

What the AI does

Maps each gathered gap to specific NIST 800-53 controls and produces the gap analysis.

Files Analysis AI

What it does

Scans a client's uploaded documents (Hebrew/English images, PDFs, forms) to identify what kinds of data the organization holds.

What the user can do

Select a file and have the AI identify the data types in it, with new/unexpected types flagged.

How they do it

They pick a file and run the analysis.

What happens

The AI extracts the data types; results roll up into a per-client consolidated data report linked to systems.

What the AI does

Reads the files (including Hebrew/English images, PDFs, and forms) and identifies the data types present, flagging any new or unexpected ones.

Systems & Continuity

Org Systems Analysis AI

What it does

Builds a full understanding of each client IT system — what it is, how data flows, how it measures against standards, how risky it is. The system list is derived from table-questionnaire answers.

What the user can do

Pick a system and let the AI analyze it end to end; watch risk scores update as remediation happens.

How they do it

They select a system from the auto-built list and run the analysis.

What happens

The AI draws a data-flow diagram, writes documentation, checks against standards, scores risk, and drops fixes into the Workplan. A "mitigated score" updates as fixes land; results appear in the client's Systems Analysis view.

What the AI does

Draws the system's data-flow diagram, writes its documentation, checks it against the standards (controls met vs. gaps), scores its risk, and emits the recommended remediation tasks.

BCP AI

What it does

Builds the client's business-continuity picture — which processes are critical, what downtime costs, and how to recover. Processes derived from table questionnaires.

What the user can do

Review each process's impact analysis, cost exposure, and recovery plan generated by the AI.

How they do it

They open a client's processes (extracted automatically) and run the BCP analysis.

What happens

Per process the AI works out recovery objectives and criticality, estimates downtime cost and annual loss, drafts recovery steps, and draws a flow diagram — surfaced in the client's BCP dashboard.

What the AI does

Runs each process's business-impact analysis (recovery objectives, criticality), estimates downtime cost and annual loss, drafts the recovery steps, and draws the process flow diagram.

Supply Chain

Supply Chain Management AI

What it does

Manages a client's third-party/vendor risk — sending vendors questionnaires and document requests, then scoring each vendor's risk.

What the user can do

Assign questionnaires and required documents to vendors, review the AI's risk analysis, and produce a consolidated supply-chain report.

How they do it

They assign questionnaires/documents to vendors; vendors respond (vendor surface — out of scope); the admin reviews the AI analysis.

What happens

The AI scores responses against requirements, reviews documents, sets a risk level per vendor, and assembles a report; the client sees a vendor risk matrix.

What the AI does

Scores each vendor's responses against the requirements, reviews their uploaded documents, sets an overall risk level per vendor, and assembles the consolidated report.

Training

Program AI

What it does

Plans and produces the client's security-awareness training — programs per department, generated content and instructor kits, scheduled sessions, and post-training competency scoring.

What the user can do

Define a program, generate content and instructor materials, schedule sessions, issue a public link for employees to answer post-training questions, and review competency.

How they do it

They define the program (department, modules, topics) and let the AI generate content, kits, scenarios, and a session plan; they schedule sessions and generate a one-time 24-hour public link.

What happens

Employees answer via the link without an account; the AI scores competency and produces a progress report; gaps flow into the Risk Management training lane.

What the AI does

Generates the training content per module, builds the instructor kits, creates custom scenarios and a session plan, and scores employee competency into a progress report.

Outputs

Workplans AI

What it does

The single place all remediation work converges — every gap found anywhere drops a recommended task here.

What the user can do

Review accumulated and manual tasks, have the AI break complex tasks into sub-steps with effort/cost estimates, assign owners, and track progress.

How they do it

They pick a client, review the task list, and move tasks draft → approved → in progress → completed; owners update percent-complete.

What happens

Tasks are tracked to completion and also surface to the client in their Workplans/Monitoring views.

What the AI does

Breaks complex tasks into sub-steps and estimates the effort and cost for each.

Reports AI

What it does

Produces the formal, polished compliance report — the deliverable the client pays for — built section by section and exported as a PDF. Generated in one selected language at a time (Hebrew by default; Hebrew, English, Arabic, Russian, or French), never mixed.

What the user can do

Pick a client and sections to include, let the AI write each section, and produce the final PDF.

How they do it

They select the client and report sections and trigger generation.

What happens

The platform aggregates the client's data; the AI writes each section including a controls-assessment table and a remediation-plan table; the sections compose into a downloadable PDF.

What the AI does

Writes each section of the report (executive summary, methodology, findings, etc.), including the controls-assessment table and the remediation-plan table.

AI Assistant

BNAI Agent AI

What it does

A conversational AI assistant the admin can ask compliance questions of, drawing on the platform's knowledge (standards, policies, and the user's organizational context).

What the user can do

Ask questions in a chat and get context-aware answers, with follow-ups remembered.

How they do it

They type a question into the chat window.

What happens

The assistant pulls in relevant context and streams back an answer; the conversation is kept so follow-ups stay on topic.

What the AI does

Retrieves the relevant context (standards, policies, the user's organizational context) and generates the conversational answer.

The admin sidebar also includes two external launcher linksClient Portal and Vendor Portal — that simply open the customer and vendor login pages in a new view. They aren't admin screens themselves, so they're not detailed above. (The admin sidebar has 26 entries total: the 24 working screens grouped above, plus these 2 launchers.)

Customer Portal the MSSP's clients

Mostly read-only. Real inputs: filling assigned questionnaires, uploading documents/policies, building org structure, managing the vendor list, ticking off remediation. Organized as 6 top domains, each with its own sub-menu. On login they reach their Compliance dashboard; if access is off or the annual license lapsed they hit an "Annual License Expired" screen.

Domain 1 — Compliance

Compliance Dashboard

What it does

The landing overview of compliance health — a headline score plus breakdowns by systems, policies, security risk, and questionnaires.

What the user can do

Read overall Compliance Score and Mitigation Progress, see analyzed/approved counts, review assigned questionnaires with status, and scan the main compliance tasks.

How they do it

View-only — they open it and scroll the cards and progress bars.

What happens

Numbers and bars reflect current data and recalculate as work is completed elsewhere.

Compliance Framework

What it does

A consolidated checklist of every outstanding compliance task — pending questionnaires, pending policy submissions, security vulnerabilities, and a systems work-plan table.

What the user can do

See an overall percent-complete bar, expand each category, click a system row to open its gaps and tick them off, and translate a section to Hebrew.

How they do it

They expand a category, and for systems click a row to open a "gaps found" pop-up where they check off each gap.

What happens

Checking gaps updates that system's mitigation status and projected score; bars move. Most rows link back to where the work is actually done.

Organization Systems (Questionnaires) primary client input

What it does

The questionnaire workspace — the main place the client provides information. Lists assigned questionnaires with status.

What the user can do

Start a pending questionnaire, continue a draft, preview questions, view/re-edit a submitted response, and upload/manage organization files.

How they do it

They click Start/Continue, answer each question (text, choices, tables, attachments) — work auto-saves — and click Submit; documents go through the upload buttons.

What happens

Submitting marks it Completed and feeds answers into the platform — table questionnaires auto-populate the "systems" list used by Systems Analysis, Data Flow, BCP, and more. A confirmation shows and counters update.

Organizational Structure client input

What it does

A form describing the organization: basic details, departments, and roles per department.

What the user can do

Review auto-filled details, edit them, add/remove departments and roles, add/remove organizations, upload an org-chart file, and download the structure.

How they do it

They expand sections, type into fields, and use Add/Remove buttons; changes save automatically.

What happens

The saved structure becomes the backbone for training programs, BCP impact analysis, process costing, and monitoring.

Policies & Procedures (Required Documents) client input

What it does

Lists the policy documents the client must submit, grouped by set, each with a status (Pending → Submitted → Under Review → Approved/Needs Revision/Rejected).

What the user can do

Read guidelines, upload the required document (or a revision), view their submission, withdraw one under review, delete a rejected one, read admin feedback, and open the finalized policy for approved items.

How they do it

They click "Upload Document," pick a file (PDF/CSV/PNG/JPG), and confirm; click the Feedback badge to read notes; click "View Policy" to open the finished document.

What happens

Uploading sets it to Submitted and sends it for MSSP review; withdrawing/deleting resets to pending. Status badges and the dashboard update.

Document Analysis

What it does

A read-only view of how submitted policy documents were assessed — statuses, scores, analysis, and annex documents.

What the user can do

Browse documents, see approval status and scores, open analysis details, and view annexes.

How they do it

They scroll the list and click a document to expand its analysis.

What happens

The analysis is displayed for reading; uploading happens in Policies & Procedures.

Org. Standard Framework

What it does

Lets the client browse the requirements (clauses and annexes) of standards relevant to them.

What the user can do

Tick standards to view, see clauses/annexes as cards, and click a clause to open its implementation guide.

How they do it

They check a standard's box; requirements load; they click a clause to read guidance.

What happens

Their selection is remembered. Reference material; if an admin hasn't generated requirements yet, it shows an empty state.

Systems Analysis

What it does

Shows each system (from table questionnaires) as a card with its AI compliance analysis, score, risk level, and data classification.

What the user can do

Browse cards, open a system's full analysis, translate it to Hebrew, and generate/open a printable report.

How they do it

They click a card to open the analysis, then use translate and print buttons.

What happens

The analysis opens for reading; the report opens in a printable window. Un-analyzed systems point the client to their administrator.

Data flow & Data classification

What it does

Per-system view of data handling — data types, hosting, database classification, security level, and data-flow detail.

What the user can do

Browse systems, open a data-detail form, view/generate data-flow diagrams and required-security-document reports, and view classification.

How they do it

They click a system to open its form, fill/confirm fields, and use report buttons (with a language choice); reports open in pop-ups.

What happens

Saved details feed the system's classification and the Final Report; generated reports are stored and reopenable.

Final Report

What it does

The consolidated final compliance report, organized into standard sections (cover, executive summary, legal basis, methodology, findings, remediation plan, management decisions, appendices).

What the user can do

See which sections exist, open the full report, open the management-decisions and systems-risk summaries, and print.

How they do it

They click "View Full Report" (and the management/risk buttons), then print.

What happens

The finished report is presented for reading/printing; the client consumes the MSSP's output here.

Domain 2 — Security

Main Dashboard

What it does

A visual summary of security posture across all testing types, with risk scores, severity breakdowns, and charts.

What the user can do

Read overall and per-method risk scores, view charts, and jump to a method's detail tab.

How they do it

View-only; read the cards/charts and click through.

What happens

Charts reflect the latest uploaded findings; links open the matching sub-tab.

Security Tools

What it does

Shows the security tooling assessed for the client, grouped by segment (endpoint, network, identity, cloud), with findings and risk scoring.

What the user can do

Browse tools by segment, open a finding to read its details, and see risk scores and coverage charts.

How they do it

They scroll/select tools and click a finding to open its detail dialog.

What happens

Finding details and risk visuals are displayed; acting on findings happens in Workplans.

Penetration Testing / External Surface Attack / Security Assessment / Code Review

What it does

Four report viewers (same design) presenting findings from each type of engagement the MSSP performed.

What the user can do

Open each uploaded report, read its executive summary, findings with severities, and average risk score, and view evidence images.

How they do it

They click a file to open its analysis; click a finding/image to enlarge.

What happens

The selected report's findings are shown for reading. View-only — the client doesn't upload test files here.

Reports Planned — not yet built

Intended purpose: a consolidated security report for the client. Currently a placeholder.

Workplans interactive

What it does

The remediation workspace for security findings — track and prove progress on fixing each finding, per method or per tool.

What the user can do

Pick a method (or tools), pick a file/tool, mark remediation steps done per finding, add comments, and upload evidence.

How they do it

They select a method, choose a file/tool, open a finding, tick its steps, type notes, attach evidence, and Save (also auto-saves).

What happens

Progress is stored against each finding and reflected in the Security dashboard and Monitoring rollups.

Domain 3 — Supply Chain

Main Dashboard

What it does

Overview of vendor/supply-chain risk — vendor counts, risk distribution, summary charts.

What the user can do

Read vendor risk tags, counts, and charts; navigate to a sub-tab.

How they do it

View-only.

What happens

Charts reflect the current vendor list and analyses.

Vendor Management client input

What it does

The client's vendor register.

What the user can do

Add, edit, and delete vendors (services, contacts, type, risk, compliance status, contract dates, notes); search; copy a vendor-portal link; bulk-import from CSV (one authorized account).

How they do it

They click Add/Edit to open a form, fill it, and save; use the search box; click delete to remove.

What happens

Saved vendors populate every other Supply Chain tab; a copyable link lets vendors fill questionnaires.

Vendors Questionnaires

What it does

Shows, per vendor, which questionnaires were assigned and their response status.

What the user can do

Pick a vendor to see its questionnaires; open a submitted response to view it.

How they do it

They click a vendor to expand its questionnaires, then click one to open the viewer.

What happens

The vendor's response is displayed read-only (vendors fill these via the separate vendor link).

Vendor Files

What it does

Browse files attached by vendors, with optional AI analysis of a file.

What the user can do

Choose a vendor, then a questionnaire or document, then a file; view it; trigger/read an AI analysis.

How they do it

They drill vendor → source → file via dropdowns, then view or analyze.

What happens

The file opens; analysis results are shown/stored for that file.

Systems & Services client input

What it does

Maps which of the organization's systems each vendor supports, with service-criticality and SLA details.

What the user can do

Assign systems/services to vendors, set severity (critical/moderate/basic) and SLA expectations, and save.

How they do it

They select systems, set the fields, and click Save.

What happens

These vendor-to-system links feed the supply-chain risk view, BCP, and the SCRM policy.

Risk Assessment AI

What it does

Assesses each vendor against a chosen standard, producing per-vendor gap analyses and scores.

What the user can do

Choose a standard, run/view AI risk analysis per vendor, open a vendor's detail panel, and view requirements.

How they do it

They pick a standard; saved analyses load and each vendor's panel can be opened.

What happens

Per-vendor scores, risk levels, and gaps are displayed/saved and roll up into Compliance Tracking and the Final Report.

What the AI does

Analyzes each vendor against the chosen standard, producing per-vendor gap analyses and risk scores.

Compliance Tracking

What it does

A consolidated view of every vendor's compliance status — scores, risk levels, and the systems each vendor touches.

What the user can do

Expand each vendor to see standards analyzed, scores, risks, and linked systems.

How they do it

View-only; click to expand a vendor.

What happens

Displays the aggregated vendor compliance picture for reading.

Final Report

What it does

A consolidated supply-chain report bringing together vendors, gap analyses, system links, scores, and risks.

What the user can do

Read the assembled report and download it.

How they do it

They open the tab and use the download button.

What happens

The finished report is presented/downloaded.

SCRM Policy AI

What it does

Generates and stores a Supply Chain Risk Management policy tailored to the client's actual vendor ecosystem.

What the user can do

Generate the policy, read it, regenerate it, save it, and download it.

How they do it

They click Generate; the system drafts it from their vendor data; they review and Save/Download.

What happens

The generated policy is stored and can be reopened, regenerated, or downloaded later.

What the AI does

Drafts the Supply Chain Risk Management policy from the client's actual vendor data.

Domain 4 — Training

Renamed from "S.E.T" for consistency — S.E.T is the system name. The MVP code still labels this domain "S.E.T".

Main Dashboard

What it does

Overview of training posture — average scores by department and standard, with charts.

What the user can do

Read score bands, per-department and per-standard averages, and summary charts.

How they do it

View-only.

What happens

Charts reflect programs, sessions, kits, and employee questionnaire submissions on file.

Training Programs AI

What it does

Builds/views training requirements and per-department programs for a chosen standard.

What the user can do

Pick a standard, generate or view requirements, generate per-department programs, and open a department's program detail.

How they do it

They select a standard, click to generate, and open a department to view its program.

What happens

Generated requirements/programs are saved and become the basis for kits and the annual plan.

What the AI does

Generates the training requirements and the per-department programs from the chosen standard.

Training Kits

What it does

A library of instructor/training kits, organized by department and standard.

What the user can do

Browse kits by department then standard and open a kit to view its contents.

How they do it

They drill department → standard → kit and click to open the viewer.

What happens

The selected kit opens for viewing.

Annual Training Plan

What it does

A month-by-month schedule matrix of training modules across a two-year horizon.

What the user can do

View the schedule grid and open a kit/module from the matrix.

How they do it

They read the matrix and click a scheduled module to open it.

What happens

Shows the planned training calendar; opening a module shows its kit.

Training Questionnaires

What it does

The training/awareness questionnaires (employee Q&A) available to present or review.

What the user can do

Browse questionnaires and open the employee Q&A presenter to run/review them.

How they do it

They click a questionnaire to open the presenter.

What happens

The questionnaire content is presented for delivery/review.

Submitted Questionnaires

What it does

Shows employees' submitted training questionnaires with scoring and analysis.

What the user can do

Browse submissions, view score bands and averages, and open an individual submission's analysis.

How they do it

They scroll the list/charts and click a submission to view details.

What happens

Submission scores and analysis are displayed and roll into the training dashboard.

Policy Evaluation Planned — not yet built

Intended purpose: evaluate training against policy requirements. Currently a placeholder.

Detail Analysis Planned — not yet built

Intended purpose: deeper per-employee/per-topic training analysis. Currently a placeholder.

Domain 5 — BCP (Business Continuity)

Main Dashboard

What it does

A readiness overview for business continuity — incident-response readiness, business-impact coverage, and remediation progress.

What the user can do

Read continuity-readiness scores and risk labels and navigate to sub-tabs.

How they do it

View-only.

What happens

Scores reflect current system risk and continuity data.

Process Map AI

What it does

Maps the organization's operational processes to departments (AI-assisted, Hebrew/English aware).

What the user can do

View processes grouped by department, auto-classify processes into departments, review priorities, and open process detail.

How they do it

They trigger AI classification and review/adjust the mapping.

What happens

The mapping is saved and feeds Business Impact Analysis, Process Cost, and Monitoring.

What the AI does

Classifies the organization's processes into the right departments (Hebrew/English aware).

Process Data Flow AI

What it does

Per-process detail showing which systems and vendors each process depends on, with flow diagrams.

What the user can do

Expand processes, assign systems (manually or via an AI bulk generator), generate flow diagrams, set owners, and view summaries.

How they do it

They expand a process, pick systems, run the generators, and open diagrams.

What happens

Assignments and diagrams are saved per process and feed BIA, costing, and continuity planning.

What the AI does

Bulk-generates the system dependencies for each process and draws the process-flow diagrams.

Process Cost AI

What it does

Calculates the cost of running each process (people, systems, vendors, overhead) and compares manual vs. AI/automated cost.

What the user can do

Enter cost inputs per process, use AI estimators to auto-fill, save, view a summary, and generate a cost report.

How they do it

They fill the fields (or run the AI estimators), then Save; they open the summary and report.

What happens

Saved cost data drives the savings figures in the Monitoring dashboard and the cost report; totals recompute live.

What the AI does

Estimates the cost inputs and auto-fills the costing fields.

Business Impact Analysis

What it does

A full BIA table per process (recovery objectives, maximum tolerable downtime, operational/financial/legal/reputational impacts, recovery priorities, minimum resources, criticality).

What the user can do

Pick a department, view its processes' BIA records, and open a formatted BIA viewer.

How they do it

They select a department, load its processes, and open the BIA view.

What happens

The detailed BIA is displayed for reading and feeds continuity readiness.

Business Continuity Plan · Org. Risk Management · Data Recovery Plan · Workplan · Reports Planned — not yet built

Intended purpose: the planning/output half of BCP — the assembled continuity plan, org-level risk register, data backup/recovery procedures, continuity remediation tasks, and continuity reports. All five are currently placeholders. (The data-gathering half above is built.)

Domain 6 — Monitoring

Main Dashboard

What it does

An operational/financial monitoring overview by department — process counts, automation status, and projected savings (manual vs. AI cost).

What the user can do

Read per-department process counts, savings figures, and an automation pie chart; open a department to see its processes.

How they do it

View-only with a click-to-expand department view.

What happens

Figures are computed from the process map and saved process-cost data.

Workplans Management

What it does

A roll-up of remediation progress across the security methods, showing percent-complete per workplan.

What the user can do

Select a method and read progress cards (done/total, percent complete) per area.

How they do it

View-mostly; they pick a method and read the bars.

What happens

Progress reflects the remediation tracked in Security → Workplans.

Compliance Analysis · Security Analysis · Training Analysis · Business Processes Planned — not yet built

Intended purpose: cross-cutting trend analyses per domain. All four are currently placeholders.

Cross-Portal Flows Admin ↔ Customer

A. Onboarding & access control. Admin creates the client and turns access on; sets up their login; the client signs in. If access is off or the annual license lapsed, the client hits the "License Expired" wall — the recurring-revenue control point.
B. Questionnaire lifecycle (core data loop). Admin creates a questionnaire (by hand, AI, or CSV) and assigns it → client fills and submits → admin reviews under Responses, re-opens if needed → client edits and resubmits. Table answers become the client's system/process inventory used everywhere downstream.
C. Document collection & grading. Client uploads existing policy documents → admin is alerted on the Dashboard, runs AI gap analysis in Compliance Documents, sets a verdict → client sees the status and required revisions.
D. Policy production & delivery. Admin drafts a client-specific policy (AI-written, admin-refined) and approves it → the approved policy becomes viewable/downloadable by the client.
E. Systems / continuity analysis → client visibility. Client submits table questionnaires → admin runs Org Systems Analysis and BCP (AI diagrams, gap/risk, impact, recovery) → outputs appear in the client's Systems Analysis, Data flow, and BCP views.
F. Security testing → findings → remediation. Admin uploads security test results, AI extracts and explains findings → client views them in their Security domain and tracks tasks in Security → Workplans.
G. Risk-and-workplan convergence. Every analysis emits gaps → they converge in Risk Management (NIST mapping, accept/mitigate/transfer/avoid) and Workplans (assignable tasks with AI-estimated effort/cost) → tasks surface to the client in their Workplans/Monitoring views.
H. The final report. Admin compiles everything into a formal PDF in Reports (one selected language — Hebrew default; English/Arabic/Russian/French also available) → client downloads it from "Final Report" — the headline deliverable.

Status & Placeholders

Both portals are documented at full per-tab depth. The only items not described in full behavior are genuine placeholders in the current code:

Still placeholders (planned, not yet built):

  • Security → Reports
  • Training → Policy Evaluation, Detail Analysis
  • BCP → Business Continuity Plan, Org. Risk Management, Data Recovery Plan, Workplan, Reports
  • Monitoring → Compliance Analysis, Security Analysis, Training Analysis, Business Processes

Everything else listed is built and functional in the current MVP. This report is the review copy; once approved it becomes the closing user-flow section of the formal specification document.