Organisation settings
Organisation details and profile, document branding for exported reports and policies, email notifications, the audit log, and deleting the organisation.
Organisation-wide settings live under Settings, which only an organisation admin sees. Most are tabs of Organisation Management; the audit log has its own entry, Settings → Audit Log. People and API keys are covered in Users and access and API keys, and the Agents tab in AI Sidekick.
Organisation details
The Organisation Settings tab holds:
- Organisation Information: rename the organisation; its identifier is shown for reference.
- Timezone: the default for reports, notifications and dates.
- Organisation profile: country, sector, size and data sensitivity, set during onboarding and shared by every project. They shape which standards are recommended. The rest of the profile and your review cadence are on Preferences.
Document branding
Exported PDF and Word documents, which today means assessment reports and policies, carry CISO360AI branding until you save your own. Document branding on the same tab sets:
- your logo (PNG or JPEG);
- a primary colour;
- footer text;
- a cover note shown on the cover of every exported document.
Choose Save branding to apply it; every export from then on carries it. Reset to defaults removes all four and returns exports to CISO360AI branding.
Your own branding needs a paid plan. On the Free plan the card explains this, and exports keep CISO360AI branding. If a plan later stops including it, saved branding is kept and applies again once it does. Other reports print from your browser and aren't affected.
Notifications
The Notifications tab decides which emails the platform sends about your organisation, and to whom. Nothing changes until you choose Save Notification Settings; Send Test Email checks delivery first.
- Recipients: every admin by default, plus any extra addresses you add, such as a shared inbox.
- Scan Notifications: when a scan starts, completes or fails.
- Security Alerts: critical and high-severity findings, someone joining your organisation, and someone being given access to a project.
- Connector Alerts: alerts from what your connections collect, such as licences assigned beyond your entitlement or seats nobody uses. Choose how often each may arrive, so a standing issue isn't reported again after every sync.
- Digest Reports: a monthly security report and a weekly summary of scan and vulnerability activity. You can send either now as a preview.
Each person can see the notifications addressed to them under their user menu, in Account settings → Activity.
Audit log
Settings → Audit Log records who did what in your organisation, newest first, for admins only. It covers, among other events:
- people and agents changing things: registrations, invitations, approvals, role changes, triage, imports, assessments, reports, risks and proposal decisions;
- changes made by an agent, with the reason it gave and the kind of key it used;
- deletions of assets, findings, vulnerabilities and evidence, one entry per record. A deletion carried out by approving a proposal names that proposal, so you can trace it back to the agent that filed it;
- revealing an exposed password, and exporting data;
- API keys being created, used, revoked or expiring, connections being added or removed, and subscription changes.
Search by actor or resource, and narrow by action (create, read, update, delete) or by event type. Each entry's details can be shown as labelled fields or as raw data. A second tab, Notifications, lists the emails the platform has sent.
Delete the organisation
Delete Organisation, at the bottom of the Organisation Settings tab, removes the organisation for everyone. You confirm by typing the organisation's name and giving a reason, and you are signed out straight away. It can't be undone from the app; if it was a mistake, contact support straight away.
Users and access
Add people, choose their role per project, approve people waiting to join, work with guests from other organisations, and remove or restore an account.
Key terms
A glossary of the platform's terminology, covering organisation and project, AI Sidekick and MCP, and the risk/compliance/exposure vocabulary used throughout these docs.