-
Notifications
You must be signed in to change notification settings - Fork 2
User Guide
For the people doing the work : running an ISMS, preparing an audit, handling an incident, keeping a risk register honest. It is written in the vocabulary of the job rather than of the code, and it says which screen to open and what the platform will do in response.
If you are looking for how to install it, that is the technical documentation. If you are looking for the exact rules an entity is held to, that is the specifications.
| Page | What it covers |
|---|---|
| Getting started | First run, signing in, and the shape of the interface |
| Finding your way | Navigation, search, the command palette, the tasks board, the calendar, saved filters |
| The dashboard | Reading it, and rearranging it into the one you want |
| How records move | Draft, validation, archive : the governance every record runs |
| Page | What it covers |
|---|---|
| Organisational context | Scopes, issues, stakeholders, objectives, SWOT, roles, activities, indicators |
| Assets and suppliers | Essential and support assets, CIA valuation, dependencies, SPOF, suppliers, contracts, certificates |
| Compliance | Frameworks, requirements, assessments, findings, nonconformities, action plans |
| Risks | ISO 27005 and EBIOS RM assessments, the register, treatment, acceptance |
| Incidents | Events, incidents, evidence, statutory notifications, breaches, post-incident reviews |
| Trust Center | Publishing your security posture, and handling document requests |
| Reports and management review | Deliverables, and the ISO 27001 clause 9.3 review |
| Ask Cairn | The optional natural-language assistant |
| Administration | Users, groups, permissions, company settings, lifecycles, imports |
Cairn is bilingual, and every screen adapts to your language. The screenshots in this guide are of the English interface, populated with Voltara Energy, the fictional renewable-energy operator that ships as the demo dataset. If you loaded the sample data at first run, your instance looks like these pictures. If you started from scratch, it will look emptier and fill up as you work.
Two things shape what you see, and they are worth knowing before you conclude something is missing.
Your permissions. A menu entry you do not have permission to read is not greyed out, it is absent. If a colleague describes a screen you cannot find, ask what group they are in before assuming a bug.
Your scopes. Cairn filters records to the organisational perimeters you are assigned. Two people looking at the same risk register can honestly see different numbers, and neither is wrong. Scopes explains the mechanism.
Built from docs/ at v0.36.0. Edits made here are overwritten by the next release : open a pull request against the source instead.
- Administration
- Ask Cairn
- Assets and suppliers
- Compliance
- The dashboard
- Finding your way
- Getting started
- Incidents
- How records move
- Organisational context
- Reports and management review
- Risks
- Trust Center
- Architecture
- Configuration
- Contributing
- The documentation system
- Installation
- Internationalisation
- Operations
- Release process
- Security
- Testing
- Adding an assistant provider
- Adding a dashboard widget
- Adding a domain entity
- Declaring a lifecycle
- Adding an MCP tool
- Adding a REST endpoint
- Adding a report
- Interface conventions
- Dashboard widgets
- Lifecycles
- MCP tools
- MCP tool parameters : Assets
- MCP tool parameters : Compliance
- MCP tool parameters : Governance and context
- MCP tool parameters : General
- MCP tool parameters : Incidents
- MCP tool parameters : Reports and management review
- MCP tool parameters : Risks
- MCP tool parameters : System and administration
- MCP tool parameters : Trust Center
- Management commands
- Models
- Permissions
- REST endpoints
- Environment variables
- MCP server
- REST API
- Assistant module (Ask Cairn)
- Module 0: User Management and Access Control
- Module 1: Context and Organization
- Module 2: Asset Management
- Module 3: Compliance
- Module 4: Risk Management
- Module 4 bis - EBIOS Risk Manager
- Module 5 : Trust Center
- Module 6 : Security Incident Management
- Management review : ISO 27001:2022 compliance (clause 9.3)