Skip to main content

Nine agents for one management system

Nine agents for the parts of compliance nobody owns.

Risk, continuity, incidents, suppliers, awareness, governance, assurance and the documents all of them feed. Each one does a real job. One of them you can buy today.

Agents in the fleet
9
Available to buy today
1
Still in build, and labelled
4

The Problem

Compliance is a dozen jobs handed to one person.

Someone has to assess the risks, prove the business could survive a disruption, handle incidents against a legal clock, chase suppliers for certificates, make awareness material people remember, agree objectives with leadership, and track every finding to closure.

Usually that someone is one person who also has another job. So the work gets done as a set of documents, each written once, each going stale the moment it is filed, and each re-written from scratch the month before an audit.

Two Ideas

Everything else follows from these.

A document is a snapshot, not an artefact.

The register is the truth. A policy or a plan is rendered from it when someone needs one, then thrown away. That is why there is no document management system here and there is not going to be one: keeping the record right is the entire job.

The agent proposes. You decide.

No agent signs anything off, closes anything, or records a verdict on its own authority. Every change is shown to you first and written only when you say so. That is not a limitation we plan to remove: it is what makes the output usable as evidence.

See where the gate sits, and what else we commit to

The Roadmap

Six moves, in the order they pay off.

  1. 1

    Quantify the risk

    Stop colouring risks in. Express them as money, so a board can compare a risk against the cost of preventing it.

  2. 2

    Generate the documents

    Keep the register right and render the policy, the plan or the minutes from it whenever anyone asks.

  3. 3

    Close the loop

    Capture each finding against the audit that raised it, and come back later to ask whether the fix held.

  4. 4

    Reach the whole organisation

    Move awareness out of an annual completion percentage and into the moments where behaviour is actually decided.

  5. 5

    Extend past your own walls

    Suppliers, devices and the parts of your estate that fail quietly rather than loudly.

  6. 6

    Make it one system

    One authoritative record behind every agent, so the same fact never has to be maintained in two places.

One System

Nine agents. One graph between them.

They do not share a runtime. What keeps them consistent is the graph underneath: the live map of your assets, people, processes and controls, held to an ontology, so a supplier, an incident and a control are typed things with typed relationships.

That structure is also what keeps the agents accurate. No agent is handed the whole graph and asked to find the relevant part. Each one queries the slice its job actually needs, which is a far harder thing to get wrong.

Risk

Continuity

Incidents

Suppliers

Awareness

Endpoints

Documents

Assurance

Governance

One graph

typed by a shared ontology

The Fleet

Nine agents, labelled honestly.

What the labels mean, honestly

Available now
Buy and install it today.
Running
Used in the compliance work we deliver, and settled in behaviour, but not sold as a standalone product yet.
In build
A prototype. It runs and produces real output, but its contracts may still change.

One of the nine is available to buy today. We would rather show you the whole fleet and label it accurately than list nine products and let you find out later that eight of them are not for sale.

What It Costs

Buy one, or run the whole system.

One agent, one time
€250
All nine, per month
€875
Per-seat charges
0

The fleet price includes every new agent and every new version as it ships, and the graph backend as it rolls out.

Which Agent When

Start from the job, not the tool.

Understand and quantify what a breach would actually cost
Risk Investigation Agent
Prove you could keep operating through a disruption
Business Continuity Agent
Handle an incident against the notification clocks
Incident Response Agent
Keep on top of suppliers and their certifications
Supply Chain Agent
Produce a policy, plan or set of review minutes
Documentation Agent
Agree scope, objectives and measures with leadership
Governance Agent
Track a finding to closure and check the fix held
Assurance Agent
Make awareness material that people remember
Awareness Training Agent
Keep the device register trustworthy
Endpoint & Usage Agent

The Clause Walk

Seven clauses, and who answers each one.

The standard runs from clause 4 to clause 10. Most of it is not about security technology at all: it is about deciding what you are protecting, agreeing what you will do, doing it, and being able to show afterwards that you did.

  1. Clause

    4

    Where the line is drawn

    Decide what the management system covers and what it does not, and be able to defend the boundary. Everything downstream depends on it, because there is no risk assessment without something to assess.

    Who Governance reasons the boundary with leadership. Documents renders the scope.

  2. Clause

    5

    Leadership actually signs

    Top management owns the policy rather than delegating it. The commitment is not a separate certificate: it is a named person putting their signature on the apex policy.

    Who Documents renders the policy. The substance stays leadership's.

  3. Clause

    6

    The hub: risks, objectives, and what you will do about them

    Work out what could go wrong, what it would cost, what you are aiming for, and which controls apply. This is the largest single piece, and the one most often done badly.

    Who Risk Investigation quantifies exposure. Governance sets objectives and measures. Documents renders the applicability statement.

  4. Clause

    7

    The support that makes it real

    People who understand what is expected of them, and records that exist because the work happened rather than because an audit is coming.

    Who Awareness runs the campaigns and the acknowledgements. Endpoints keeps the device register honest.

  5. Clause

    8

    Running it

    The operating parts: incidents when they happen, suppliers as they change, and a continuity plan that has been exercised rather than written.

    Who Incidents, Suppliers and Continuity, each writing to the register the others read.

  6. Clause

    9

    Checking whether it works

    Measure, audit internally, and hold a management review that reaches actual decisions. The review is where the year's evidence is supposed to add up.

    Who Governance runs the review cycle. Assurance rolls up the audit findings.

  7. Clause

    10

    Fixing what did not

    Nonconformities tracked to closure, and the part most systems skip: going back later to check the fix actually worked.

    Who Assurance, from the finding that raised it through to re-verifying the fix.

What You Get

The documents an auditor actually asks for.

Every one of these is generated from your registers, which means it is current when you produce it rather than current when someone last remembered to update it.

  • Risk register, quantified in money
  • Statement of Applicability inputs
  • Business continuity plan and testing schedule
  • Incident records aligned to the notification clocks
  • Supplier register, certifications and exit plans
  • Policies, procedures and intent statements
  • Management review minutes and the brief behind them
  • Corrective actions, tracked to closure

The Year

A management system has a rhythm.

5 to 7

hours a week

Inner rings beat faster. The outer ring turns once.

  • Weekly52 times a year

    Log what went wrong, close open actions, keep the registers current.

  • Monthly12 times a year

    The awareness campaign goes out, and the device register gets its gaps chased.

  • Quarterly4 times a year

    Check the objectives and measures still hold, and re-check the suppliers that changed.

  • Half-yearlyTwice a year

    A checkpoint: re-run risk where the business actually moved, before it is the annual one.

  • YearlyOnce a year

    The management review, the internal audit, the continuity drill, and the external audit itself: surveillance most years, recertification every third.

Almost all of it is the weekly beat. What people picture when they think of compliance is the outermost ring, and it turns once.

The fleet is built around that shape. The fast agents keep their registers current so the slow ones have something true to read, and the annual review is where the two meet. Certification is kept, not achieved.

Only the external audit runs on someone else's calendar. The rest is the tempo this work naturally falls into rather than a schedule the standard imposes: it asks for planned intervals, not particular ones, so those are yours to set.

The Certificate

Certification is a three-year loop, not a finish line.

  1. Year 0

    Stage 1, then Stage 2

    The full stand-up. Scope, risk, documents, the operating agents, then a first internal audit and management review. This is the year that is actually hard, and the certificate at the end of it reflects work your team genuinely did.

  2. Year 1

    Surveillance, sampled

    A lighter audit that asks a different question: is the system run, or only documented? Risk is re-run where things changed, and a year of evidence either exists or does not.

  3. Year 2

    Surveillance, different sample

    The same annual rhythm against a different slice. A continuity exercise, effectiveness re-checks on the fixes from year one, and nothing to manufacture if the registers were kept current.

  4. Year 3

    Recertification, full scope

    The whole system re-audited for a fresh three-year certificate. A full risk re-assessment, the complete document set regenerated, and the cycle starts again.

Because every document renders from a live register, recertification is a re-run rather than a rebuild. The path through the standard is the same for everyone. What the fleet changes is that the work is already real, and already written down, before the auditor asks.

Under The Hood

Nine separate agents that do not drift apart.

These are separate agents with no shared runtime, which raises an obvious question: what stops them contradicting each other?

The answer is that the facts they publish are generated from one source and checked automatically on every change, rather than being copied by hand and kept in step by whoever remembers. Anything that drifts fails the build.

There is also a maintenance layer that watches the codebase itself and raises a change request when something starts to diverge. You will never interact with it. It exists so that the version numbers, capabilities and claims on this page are true because they were derived, not because someone checked.

Get Started

Begin where the value is provable.

The Risk Investigation Agent is the one you can buy today, and it is also the right place to start: the rest of the system is far easier to build once you know what your risks are worth.

Common Questions

What people ask about the fleet.

Need help?

Submit a request below and we'll get back to you within one business day.

No file chosen

We process your data to handle your support request and respond to you. See our Privacy Policy.

Or email us at support@askara.solutions