Introduction# Welcome to RiskPilot <span class="badge-status">Available</span> RiskPilot is a **governance, risks and compliance (GRC)** platform. It centralizes the context, cyber scenarios, processing, controls, evidence and management of the information security management system (ISMS). ## Who is the platform for? - **Administrator**: organization, users, messaging, integrations and audit. - **Risk manager**: inventory, risks, governance and treatment plans. - **Action owner**: assigned actions, progress, comments and proofs. - **Auditor**: insurance work according to his permissions. - **Reader**: reading access. This technical role is not offered as an assigned role in the interface. ## Essential concepts The **organization** constitutes the multi-tenant boundary: a resource and its relationships must belong to the same tenant. Hiding a button in React makes it easier to use, but the Symfony API remains the security authority. The main path is: perimeter → active → threat and vulnerab