Skip to main content

Client Portal

The Client Portal is the entry point to Compliance OS. It gives each authorized client a dedicated context and helps users move to the applications relevant to their responsibilities.

What you see after sign-in

The portal can present:
  • the client organization you are currently operating within,
  • applications you are authorized to open,
  • current tasks assembled from authorized applications,
  • recent client-safe activity,
  • selected metrics from available applications,
  • program-level status when the Security Program Hub is authorized and provides it.
The exact dashboard is intentionally dynamic. A participant may see interview and remediation information, while an executive may see governance-oriented information.

Application access

The portal can direct you to:
  • Interview Application for assigned stakeholder interviews,
  • Remediation Workspace for findings, treatments, evidence, and remediation work,
  • Security Program Hub for leadership and governance workflows.
If an application is not available, that does not necessarily indicate a problem. The application may not be enabled for your client, your engagement, or your role.

Dashboard information

Portal metrics are intended to be derived from the applications that own the underlying workflow. The portal should not invent a zero, status, or task when a source application is unavailable. For example, depending on authorization, a participant dashboard may include:
  • remediation items,
  • pending actions,
  • assigned interviews,
  • evidence requests.
An executive-oriented dashboard may include:
  • active assessments,
  • open findings,
  • pending actions,
  • open risks.
The dashboard is a summary. The source application remains the authoritative place to review details and take action.
When you select an application, Compliance OS carries your authenticated client context into the child application. Each application still performs its own authorization checks before returning content. This layered approach means the Client Portal is not a universal bypass. It is the front door, while each application remains responsible for its own client-safe data boundary.

If something looks unavailable

Before assuming access is broken:
  1. Confirm you are using your organization’s correct Client Portal URL.
  2. Confirm you signed in with the account invited or provisioned for the engagement.
  3. Check whether the application appears in your portal.
  4. If the application opens but shows no assignment, verify that you were actually assigned work for that engagement.
  5. Contact your Cyber Op Source engagement lead if your expected access is missing.