Appearance
Customer Guides & Role Playbooks
Welcome to the OrviQ Customer Guides. These practical playbooks provide role-oriented operating rhythms, primary workspace maps, approval boundaries, and governance principles for users across your organization.
Unlike technical reference documentation that explains individual buttons and database fields, each guide focuses on how a specific persona conducts their operational lifecycle within OrviQ while respecting mandatory enterprise guardrails.
Select Your Persona
Choose the guide that matches your functional responsibility in OrviQ:
| Persona / Role | System Role Key | Primary Mission | Guide |
|---|---|---|---|
| Enterprise Onboarding | All Roles | 10-step sequence to establish organizational GRC operations | Quick-Start Guide |
| GRC & Compliance Officer | compliance_officercompliance_manager | Regulatory intelligence, requirements pipeline, crosswalks, gap analysis, and determinations | Compliance Officer Playbook |
| Risk Manager | risk_manager | Enterprise risk register, RCSA campaigns, KRI thresholds, and risk acceptance governance | Risk Manager Playbook |
| Control Owner | control_owner | Internal control operation, scheduled evidence uploads, self-assessments, and action plan milestones | Control Owner Playbook |
| Policy Owner / Reviewer | compliance_officercompliance_manager | Structured policy authoring, atomic operationalization, review cadences, and attestations | Policy Owner Playbook |
| Auditor (Internal / External) | auditor | Independent inspection, forward/reverse lineage validation, cryptographic evidence verification, and audit workpapers | Auditor Playbook |
| Business / Employee User | All Workspace Roles | Self-service policy review, mandatory attestation campaigns, and incident reporting | Employee Portal Guide |
| Tenant Administrator | tenant_admin | User provisioning, RBAC assignments, multi-eye workflow templates, SLA deadlines, and audit logs | Tenant Administrator Guide |
Core Governance Doctrine
Every playbook in this section enforces OrviQ's foundational Semantic Doctrine. In modern enterprise governance, terminology must reflect factual system states rather than optimistic assumptions:
Fundamental Inequations of Governance
- Mapping $\neq$ Compliance: Establishing a crosswalk relationship between a regulatory obligation and an internal control demonstrates architectural alignment; it does not prove regulatory satisfaction or compliance.
- Evidence $\neq$ Effectiveness: Ingesting or attaching an evidence artifact proves that an activity or artifact was recorded; it does not prove the control operated effectively to mitigate risk.
- Adoption $\neq$ Compliance: Adopting a certified template or policy pack into your tenant instantiates draft policies; it does not make the organization compliant.
- Published $\neq$ Compliant: Having an approved, published corporate policy establishes the governing organizational rule; it does not prove employee or operational adherence.
- Attestation $\neq$ Effectiveness or Compliance: An employee's electronic acknowledgment confirms policy communication and awareness; it does not prove operational control effectiveness or statutory compliance.
- Traceability $\neq$ Compliance / Effectiveness: Visualizing complete forward and reverse lineage from regulation to evidence proves structural auditability; it does not substitute for substantive audit testing.
- Gap Closure $\neq$ Compliance Determination: Remediating a detected shortfall addresses an identified defect; holistic compliance determination remains an independent, authorized professional judgment.
How to Use These Guides
- Read the Quick-Start Guide if your organization is newly onboarding or configuring a fresh tenant workspace.
- Consult your role-specific playbook for daily, weekly, quarterly, and annual operational cadences.
- Follow in-text links to detailed conceptual overviews and step-by-step how-to articles for advanced configuration or technical schemas.
- Use OrviQ Assistant (
Ctrl+J) within the application for context-grounded queries referencing authoritative business IDs (REQ-,CTR-,POL-,RSK-,MAP-,EXC-).