SecaniDocumentation

Getting Started

Start a Secani compliance workspace with a focused first scope.

A strong Secani setup begins with a focused information scope. Choose one representative area of the organization, collect the systems and processes that matter, and connect the evidence you already have before expanding into broader framework coverage.

Start With A Clear Scope

Pick The First Boundary

Start with one organizational unit, business process, product, or managed service. The first boundary should be large enough to show real compliance work, but small enough that owners can answer questions quickly.

Name The Owners

Assign a primary owner, a reviewer, and any subject-matter contacts before the first evidence review. This keeps follow-up tasks from drifting into a shared inbox or an informal chat thread.

Set The Review Cadence

Choose a short review rhythm for the first pass, such as weekly evidence checks or milestone-based approvals. A visible cadence makes gaps easier to close while the workspace is still small.

  • Identify the organization unit, process, or service you want to document first.
  • Add the applications, IT systems, networks, and external providers that support it.
  • Capture ownership and review responsibility early so follow-up tasks have a clear path.

Build The First Model

Add Systems And Services

Create the target objects that describe the actual systems in scope: applications, infrastructure, networks, business services, and supporting tools.

Map The Dependencies

Connect systems to the services, providers, and teams they rely on. Dependency context helps reviewers understand why one control or piece of evidence matters in more than one place.

Capture External Providers

Add cloud providers, SaaS vendors, consultants, and managed services that affect the scope. External ownership should be visible early because it often changes the evidence path.

Bring Evidence Into Context

Upload Existing Material

Upload policies, exports, screenshots, descriptions, and existing documentation where they support concrete requirements or controls. Secani works best when evidence is attached to the thing it proves, not stored as a loose archive.

Attach each piece of evidence to the requirement, control, system, or decision it supports. Linked evidence makes the later audit trail easier to inspect.

Track The Gaps

Use missing screenshots, outdated policies, unclear ownership, and open review questions as tasks. Gaps should become visible work items instead of notes hidden in a document.

Review Before You Rely On It

Check AI Suggestions

AI-generated suggestions should be treated as draft work. Review sources, adjust wording, approve the final result, and keep the decision traceable for auditors and internal reviewers.

Approve The Decision

Keep human approval explicit for control mappings, evidence conclusions, and generated summaries. The point is to speed up review work without hiding accountability.

Keep The Audit Trace

Preserve source links, comments, approvals, and timestamps around each material decision. A good trace makes future reviews faster because the reasoning is still attached to the work.