RiskPilot Website FR GitHub

ISMS documents #

Objective and access #

The menu centralizes policies, procedures, instructions, records, evidence and models. The root displays the ten most recent accessible documents; dynamic categories respect tenant and ACL.

Create a document #

Fill in title, category, status, classification, visibility, owner, Markdown content and version comment. A .doc/.docx file of up to 10 MB can complete the content.

Lifecycle and versions #

The cycle is Draft → Review → Approved → Archived. Any modification creates an immutable version, invalidates approval and revokes shares. The approver schedules the next review. A previous version can be restored by creating a new version.

ACL and sharing #

READ reads, EDIT modifies/versions, MANAGE manages ownership, ACL, approval and sharing. Only active users of the tenant are eligible. An external link requires an approved version; it is revocable and expirable. Confidential/restricted documents require a password, and restricted sharing expires in 30 days.

The open form has four tabs: Document, Versions, Access and Sharing. In the side menu, Recent Posts is fixed; the other submenus are the categories visible to the user, sorted alphabetically.

Search, archiving and issues #

Search by title/category and filter overdue journals. Permanent deletion requires confirmation and must remain exceptional. A revoked link never becomes valid again after re-approval.

Example #

Publish “Access Control Policy”, Internal classification, CISO owner, annual review, ACL READ to auditors and external sharing limited to the approved version.

Fields and publication #

Title and category structure the navigation; status and classification govern the cycle; visibility, owner and ACL control access. Content accepts Markdown and Word file, with version comment and next review.

  1. Search for an equivalent document.
  2. Create title, category, classification and owner.
  3. Write the content or attach a Word of maximum 10 MB.
  4. Save as draft with comment.
  5. Configure ACLs, submit for review and approval.
  6. Schedule the next review.

Versions and restoration #

Each change creates an immutable imprinted version of the file. Restoring an old version produces a new one. Any changes invalidate the approval and revoke existing shares.

ACL #

READ reads and downloads; EDIT modifies and versions; MANAGE manages ownership, ACL, trust and sharing. Only active users of the tenant are eligible.

External sharing #

Only an approved version is shareable. Set an exhalation; sensitive documents require a password and restricted sharing expires within 30 days. The full link is only visible upon creation.

Checks and errors #

An absentee owner is inactive or non-tenant. A denied share often indicates an untrusted document, incorrect expiration, or a missing password. A rejected file may exceed 10 MB or may not have a valid Word signature.

Best practicesUse stable categories, proportionate classification and a business owner. Review the ACLs during departures. Archive rather than delete when preservation is necessary. #