Application Settings

Configure platform, AI, security, organization, and developer preferences.

Profile & Preferences

Update your display name, personal credentials, and account session controls.


Change Password


Security Settings

Register a passkey to use as an alternate MFA method during login.

Name Created Last Used Transports Actions

Organization Settings

Manage tenant branding, compliance modules, and organization-wide operational preferences.

Directory integration is coming soon. This link will be used once the directory page is live.

Admin control. When enabled, users can use microphone dictation in AI chat. Terms and Privacy Policy prohibit entering student data, employee data, or any other regulated data.


Enable this if your company manages security for other organizations. Your MSP branding will appear alongside your client's branding on reports.


Compliance Frameworks

Enable or disable compliance modules for your organization. Disabling a framework hides it from navigation, the compliance hub, reports, and the dashboard. Your data is never deleted — re-enabling restores everything.

Appearance & Branding

Choose a curated preset first, then expand the advanced controls only if you need section-by-section branding overrides.

General Theme Selector

Curated presets

Pick a stable light or dark starting point. The presets update the overall shell while keeping semantic risk and alert colors readable.

Advanced Customization Fine-grained theme controls Open only if you need section-by-section overrides

These controls cover risk palettes, classification colors, workspace gradients, typography, motion, and icon uploads.

AI & Integrations

Configure AI providers, search APIs, email delivery, and platform integration endpoints.

OpenAI


Perplexity


Brave Search


Email Delivery

Send a test email to verify delivery is working (Graph Mail or SMTP).


ElectriCISO Scanner

Deploy a network vulnerability scanner at your client site. Native options use nmap + Nuclei; Docker adds full OpenVAS scanning.

Native Windows nmap + Nuclei
2GB RAM, no Docker needed
Native Linux nmap + Nuclei + systemd
2GB RAM, Ubuntu/RHEL/Debian
Docker (Full Stack) OpenVAS + nmap + Nuclei
8GB RAM, Docker required
Registry Advisory

Scanner version:

View setup guide


Platform Integrations

Configure connections to external platforms. Each integration has its own dedicated settings page.

🛡️
Microsoft 365 OAuth, tenant config, sync
🛡️
ConnectSecure API key, base URL, sync
6C
6Clicks Sync config, entity mapping

AI Prompts & Models

Govern the prompts, models, and generation settings used across AI-assisted workflows. Changes apply as features are wired into the shared prompt manager.

Shared Prompt Governance

Categorized prompt manager

This replaces the old flat prompt textarea. Edit prompts per workflow, reset them to defaults, and control model settings in one place. The attestation content generator already uses these saved settings.

0 Total prompts
0 Modified prompts
0 Active categories

Recommended practice: keep system prompts authoritative and conservative. Use user prompt templates only for structured variable insertion, not for hidden business logic.

Users & Access

Invite users, manage roles, and review access state for this organization.

Name Email Role Status MFA Actions

Audit Log

Timestamp User Action Resource Changes
Page 1

CrossWalker Intelligence

CrossWalker detects overlapping compliance requirements across frameworks and generates reviewable suggestions. Finalized assessment items in one framework can pre-fill related controls in other frameworks.

Full Backfill

Scan all finalized assessment items across all frameworks and generate crosswalk suggestions. Useful for initial onboarding, bulk imports, or after enabling new frameworks. Rate-limited to once per hour.

Recent Runs

Date Type Status Suggestions Mappings Checked

How CrossWalker Works

Trigger: CrossWalker runs automatically when you finalize an assessment item (mark it as "Final" with attestation). It does NOT run on drafts, autosaves, or AI-generated content.

Suggestions: Generated suggestions appear in the Compliance Hub for review. They are never auto-applied — a human must accept or reject each one.

Provenance: Every suggestion includes a full audit trail showing the source data, who attested it, when, and the confidence score.

Manual control changes: Direct updates to control statuses (outside the assessment workflow) are intentionally excluded from crosswalking because they lack the evidence trail and attestation that make suggestions defensible.

Developer Settings

These tools are only visible in development mode (localhost).

Dev Clear

Delete module data for the current organization. Grouped by top-level app modules. Use with caution.

Compliance

Risk

Operations

Email Integration

News Feed / Threat Intelligence

Threat intelligence search provider settings. Navigate to the News page to access run/debug actions.

Provider
Perplexity Model
Actions

Developer Modules

Experimental and in-development compliance modules.

Compliance