Solutions

One platform, four roles, four working surfaces.

Each role works on a tuned surface. The evidence underneath is shared, audited, and exportable to the same dossier.

PA
Platform AdminEM · Edit Mode

Own the tenant. Provision the people. Keep the audit clean.

What this role gets done
  • Stand up the tenant in under a day
  • Map SSO to your IdP and lock down provisioning
  • Audit every user action with timestamped before/after diffs
See workflow
What you getPA · EM · Edit Mode
Single tenant per organization, isolated by JWT
SCIM 2.0 provisioning into your existing IdP
Role-based access tuned to ISO 21434 phases
Region-locked data residency at provisioning time
A typical week
  1. 1
    Review pending access requests in the inbox
  2. 2
    Approve / deny with a one-line reason that lands in audit
  3. 3
    Export the weekly audit pack to your SIEM
CSO
Cybersecurity OfficerDepartment Review Mode

Set policy. Sign the dossier. Defend the program at procurement.

What this role gets done
  • Set the policy gates that decide when phases close
  • Sign off on TARA dossiers with a snapshotted decision
  • Confirm cybersecurity relevance and plan design reviews
See workflow
What you getCSO · Department Review Mode
Org-level dashboard rolling up every program
Policy gates wired to phase transitions
One-click 21434 / R155 / R156 evidence packs
Compliance posture tracked in a single audit timeline
A typical week
  1. 1
    Open the org dashboard, scan the gate breaches
  2. 2
    Sign or push back on dossiers awaiting approval
  3. 3
    Generate the monthly compliance posture export
CSM
Cybersecurity ManagerPRM · Peer Review Mode

Run the program. Coordinate the reviews. Own supply-chain CS.

What this role gets done
  • Coordinate CSPR / CSDR / CSCR / CSSR / CSAR reviews
  • Assign engineers and design reviewers, track DR ratings against milestones
  • Move review tickets through state without losing audit
See workflow
What you getCSM · PRM · Peer Review Mode
Milestone tracker across the full §8 → §10 lifecycle
Phase-gated review queues with owner SLAs
Supply-chain interface evidence per §15
Per-program risk dashboard with treatment status
A typical week
  1. 1
    Triage the review queue every morning
  2. 2
    Reassign blocked tickets to the right CSE
  3. 3
    Push the program status update to leadership
CSE
Cybersecurity EngineerTEM · Edit Mode

Ship the analysis. Author trees. Score feasibility. Defend in review.

What this role gets done
  • Build TOE asset graphs for every subsystem you own
  • Author attack trees and score feasibility
  • Derive security goals and concepts from treated risk
See workflow
What you getCSE · TEM · Edit Mode
React Flow canvas tuned for asset graphs and attack trees
170+ pre-loaded questions across SeRA / SeCa / SeCo / SeDP / SeTP
Threat-to-clause auto-correlation against R155 Annex 5
Versioned mitigation overlays you can A/B against feasibility
A typical week
  1. 1
    Pick up the highest-priority TOE in your queue
  2. 2
    Author trees, score feasibility, link mitigations
  3. 3
    Hand off the dossier to CSM with a single ticket move

Pick the workflow your team will live in.

We'll provision the right surface and the right access.