Skip to main content

Getting started

A brand-new SolveGRC workspace starts empty, and an empty GRC platform can feel like a locked room: where do you begin, and how much do you have to feed it before it gives you something real back? This page answers both questions honestly. The short version: pick a goal, follow the journey the dashboard builds for you, and expect your first meaningful insight the same day for most goals.

Pick your goal

The first time an administrator opens the dashboard, SolveGRC asks one question: What brings you to SolveGRC?

  • Get compliant with a framework — SOC 2, ISO 27001, PCI, CIS, and more.
  • Manage vendor risk — onboard, assess, and continuously monitor vendors.
  • Answer security questionnaires — AI-drafted, cited answers from your own documents.
  • See my cloud security posture — connect AWS, Azure, or GCP read-only.
  • Build continuity & DR readiness — map services, impacts, and plans.
  • Just exploring — a general tour of the foundations.

Your answer picks the journey the dashboard walks you through. It is stored on the workspace, visible to your whole team, and an administrator can change it at any time with the pencil next to the journey title. Nothing is locked in.

Follow the journey

The journey card on the dashboard lists the handful of steps between an empty workspace and your goal's first real insight. It is not a static checklist: every step is checked against your actual data, so finishing work anywhere in the product ticks the step — the card never nags you for something you have already done.

Each step tells you three things:

  • Why it matters — what the step contributes to the picture.
  • What it unlocks — the insight or capability that lights up when the step is done.
  • How to do it — a link to the right page, and for most steps a Show me how button that runs an interactive walkthrough right on the page.

How much data is enough?

This is the question every new tenant asks, so SolveGRC answers it on the dashboard rather than leaving you to guess. The Insight readiness panel lists the platform's headline insights and, for each one that is not lit yet, the single next input it is waiting on:

InsightBecomes meaningful when
Compliance scoreA framework is active and you have assessed your first controls
Vendor risk ratingsA vendor exists and has at least one completed assessment input
AI questionnaire answersA few core documents are uploaded and a questionnaire is imported
Cloud postureA cloud account is connected and its first sync has landed
Risk in dollarsA risk exists and a business service carries dollar impacts
Continuity readinessA business service is mapped with its dependencies

Two honest rules of thumb follow from that table:

Fastest first insight

Cloud posture is the quickest win: one read-only connection, and the first sync returns findings already mapped to compliance standards — no other data required. Questionnaires is a close second: upload three to five core documents (your security policy, a SOC 2 report, prior questionnaires) and the AI can start drafting cited answers the same hour.

Quality compounds

The AI features draw on your document corpus. They work with a thin corpus — they will just tell you honestly when the evidence does not cover a question. Every document you add makes every future answer, assessment, and analysis better. Feeding the platform is never wasted work.

Where things flow

Nothing you enter lives in only one place. Documents become citable evidence; evidence satisfies controls; controls roll up to framework scores; cloud findings satisfy controls and raise risks; approved questionnaire answers become evidence for the next questionnaire. The How SolveGRC fits together page draws the full map, and every module page in the app has a Connections button in its header showing the same thing for the page you are on: what it consumes, what it produces, and what it feeds.

When something is empty

An empty view in SolveGRC tells you what feeds it and offers the action (and usually a walkthrough) that lights it up. If you land somewhere blank, the page itself is the guide — and the AI assistant in the bottom-right corner can answer "how do I…" questions with citations into these docs and the in-app walkthroughs.