Skip to main content

Activate & scope

Everything starts with an activation. Until a framework is activated for your organization, it is just an entry in the catalog; the moment you activate it, SolveGRC materializes an assessment for every control it contains, and that worklist is where your compliance score comes from.

Activate a framework

On the Frameworks page, open the Catalog tab. It lists the frameworks in the global catalog; each row you have not yet activated carries an Activate button, and ones you have show an Activated badge instead.

ScreenshotThe Framework Catalog tab: a list of frameworks with an Activate button on each row that is not yet active for the organization.

Clicking Activate opens a confirmation dialog that names both the framework and the organization it will be activated for, with an optional notes field for context about the activation. The dialog is explicit about the consequence: activating seeds an assessment for every control in the framework, and your compliance score starts there.

Check the organization name before you confirm

Activation always targets the organization currently selected in the app, and the dialog shows that name in an "Activating for" callout. If you work across multiple customer organizations, this is the moment to make sure you are in the right one.

ScreenshotThe Activate dialog: the framework name in the title, the 'Activating for' organization callout, the optional notes field, and the note that activation seeds an assessment for every control.

Read the Active Frameworks tab

Once activated, the framework appears on the Active Frameworks tab. Each one expands into its control tree and carries a compliance score card: the percent compliant headline, a progress bar, and a count of how many in-scope controls are satisfied. The Assess controls page explains how to read the card in detail.

From here, Analyze Compliance on an active framework takes you to the Assessments module with that framework's worklist ready to work.

Scope what applies

Not every control in a framework applies to every organization, and a score that pretends otherwise is a lie. The Applicability tab is where you record those decisions: mark a control as not applicable, scoped out, inherited, or exception-accepted, each with a rationale and an approval. Excluded controls do not drag your compliance score down; they leave the scoring denominator instead, and the score card discloses exactly what was excluded and why.

ScreenshotThe Applicability & Exemptions tab: the workbench for marking controls not applicable, scoped out, inherited, or exception-accepted, with rationale and approval on each decision.

Two supporting panels live on the same tab:

  • Scope Profiles hold multi-scope setups: current versus target state, business units, products, regions, and customer engagements.
  • Expiring decisions lists approved decisions whose expiry date is approaching, so a temporary exception cannot quietly become permanent.
Scope early, not after the score embarrasses you

Recording applicability decisions before you start assessing keeps the score honest from day one. A framework showing 40% compliant because half its controls do not apply to you is noise; the same framework scoped correctly tells you where the real work is.


With a framework active and scoped, the work moves to the per-control worklist. Continue to Assess controls.