Skip to content

Commit e8a9e04

Browse files
committed
first draft
1 parent 57009ba commit e8a9e04

File tree

1 file changed

+121
-0
lines changed

1 file changed

+121
-0
lines changed
Lines changed: 121 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,121 @@
1+
---
2+
sidebar_position: 2
3+
sidebar_label: Quickstart Guide
4+
title: Quickstart Guide - Getting Started with Openlane
5+
description: Open-source compliance automation platform for managing security, risk, and regulatory requirements. Streamline SOC 2, ISO 27001, NIST, GDPR, and HIPAA compliance.
6+
---
7+
8+
You made it to Openlane!
9+
If you’ve just started your trial, the fastest way to understand the platform is to build something real.
10+
11+
This guide walks you through the first few steps to get your environment set up and your compliance program taking shape.
12+
13+
14+
## 1. Set Up Your Organization
15+
16+
Start by configuring how your team will access Openlane.
17+
18+
**Navigate to:** `Organization settings`
19+
20+
### What to do:
21+
- In `Authentication`, add your **allowed email domains**
22+
- Example: `yourcompany.ai`
23+
- Include domains for any **fractional support** (consultants, VCISOs) if applicable
24+
- Choose whether to **allow auto-join**
25+
- Enabled → anyone with an approved domain can join automatically
26+
- Disabled → users must be invited manually
27+
28+
:::tip
29+
If you're working with a fractional CISO or consultant, adding their domain upfront makes collaboration much smoother.
30+
:::
31+
32+
## 2. Invite Your Team
33+
34+
Compliance is a team sport. Bring in the people who are helping you build and manage your program.
35+
36+
**Navigate to:** `User Management`
37+
38+
### What to do:
39+
- Invite teammates across:
40+
- Engineering
41+
- Security / IT
42+
- HR / People Ops
43+
- Leadership
44+
- Assign roles as needed
45+
46+
:::tip
47+
**No per-user fees.**
48+
Invite your whole team — not just a “compliance owner.” The best programs reflect how your organization actually operates, so we don't charge you more for building your program the right way and growing your business.
49+
:::
50+
51+
## 3. Add a Standard
52+
53+
Next, define what you're working toward.
54+
55+
**Navigate to:** `Standards Catalog`
56+
57+
### What to do:
58+
- Click `Details` and select a relevant domain. For SOC 2, these are the Trust Services Criteria (remember, Security is the only required TSC)
59+
- Select and enable a framework:
60+
- SOC 2
61+
- ISO 27001
62+
- HIPAA
63+
- ISO 42001
64+
- You can enable **multiple frameworks** without duplicating work.
65+
66+
:::tip**Openlane is made to support your success.**
67+
Turn on only what you need now and expand later without starting over.
68+
:::
69+
70+
## 4. Upload Controls
71+
72+
Controls are the backbone of your program. They define how you actually meet requirements.
73+
74+
Full guide:
75+
https://docs.theopenlane.io/docs/platform/compliance-management/onboarding/controls
76+
77+
### What to do:
78+
- Create or import controls that reflect your **real processes**
79+
- Map them to your selected framework(s)
80+
81+
:::tip**Don’t over-engineer this.**
82+
Your selected auditor will likely provide "suggested controls", which can help you get started.
83+
:::
84+
85+
## 5. Upload Policies
86+
87+
Policies define intent. Controls prove execution.
88+
89+
Full guide:
90+
https://docs.theopenlane.io/docs/platform/compliance-management/onboarding/policies
91+
92+
### What to do:
93+
- Upload existing policies (if you have them)
94+
- Or generate new ones using Openlane's integrated AI
95+
- Link policies to relevant controls
96+
97+
:::tip**Policies don’t need to be perfect on day one.**
98+
They should evolve alongside your program.
99+
:::
100+
101+
102+
## What’s Next: Start Customizing
103+
104+
Now that you have the foundation:
105+
106+
- Refine controls to match how your team actually works
107+
- Upload real evidence from your existing tools
108+
- Assign ownership across your team
109+
110+
### Explore next:
111+
- **Registry** → Track assets, vendors, and personnel
112+
- **Exposure** → Manage vulnerabilities, findings, and remediations
113+
114+
115+
## Want Help?
116+
117+
If you want to go faster, we’ll build it with you.
118+
119+
**Book time:** https://calendly.com/kwaters-theopenlane
120+
121+
_No slides. No sales pitch. Just direct access to our experience._

0 commit comments

Comments
 (0)