Skip to content

Employee Portal & Attestation Guide

This guide defines the workflows, primary workspaces, and expectations for General Employees and Business Users in OrviQ.


1. What This Role Does in OrviQ

For most employees, OrviQ serves as the central corporate portal for:

  • Reviewing published organizational policies and standards that apply to their job function.
  • Completing mandatory annual or onboarding Policy Attestations (acknowledging policy awareness and receipt).
  • Managing individual task assignments or compliance inquiries routed to them.
  • Reporting operational incidents, data privacy events, or compliance concerns.

Every active user account in OrviQ possesses the foundational permissions (policy.attest, my_work.read) required to access these self-service functions.


2. Primary Workspaces

General employees interact with a streamlined set of self-service modules:

WorkspaceRouteKey Activities
My Policies/my-policiesView published policies assigned to your department or role; complete required attestations.
My Workbench/my-workView individual tasks, assigned evidence requests, or information requests with due dates.
Incidents Reporting/incidentsSubmit initial operational disruption or security event reports for triage.
User Profile/profileReview user account details, active role assignments, and department metadata.

3. Typical Operating Workflow

Reviewing Policies & Completing Attestations

  1. Accessing My Policies: Log in to OrviQ using your standard enterprise single sign-on (SSO) credentials. Navigate to Work & Decisions > My Policies (/my-policies).
  2. Reviewing Pending Attestations: The portal displays policies categorized into:
    • Action Required (Pending Attestation): Policies requiring your formal review and acknowledgment.
    • Completed Attestations: Previously acknowledged policies with timestamp records.
    • All Applicable Policies: The full reference library of active corporate policies.
  3. Reading Policy Content: Click on any policy card (e.g., Acceptable Use Policy, Code of Conduct, Information Security Standard). Review the structured document sections and atomic statements.
  4. Submitting Acknowledgment: Once you have read the policy:
    • Click the Acknowledge Policy button.
    • Confirm your understanding and acceptance in the confirmation dialog.
    • The system immediately logs your acknowledgment with an immutable timestamp and your authenticated user ID.

Managing Assigned Tasks

  1. Accessing My Workbench: Open My Workbench (/my-work).
  2. Checking Action Items: Review your personal task inbox for items requiring your input (such as providing feedback on a compliance activity or submitting an operational artifact).
  3. Submitting Deliverables: Click into the task, upload the requested document or notes, and click Submit.

Reporting an Incident or Operational Event

  1. Initiate Report: If you discover a security breach, privacy violation, operational disruption, or system failure, navigate to Incidents (/incidents).
  2. Provide Details: Click Report Incident. Complete the initial event form:
    • Summary and observed impact.
    • Event category (Cyber, Operational, Privacy, Financial, Third-Party).
    • Date and time of occurrence.
  3. Submit for Triage: Submit the report. It is immediately routed to the Incident Response and Risk Management teams for investigation.

4. Approvals & Segregation-of-Duties (SoD) Boundaries

Employee interactions are bounded by strict self-service controls:

  • Bounded Access Scope: General employees can only view policies published for their scope and their own assigned tasks. They cannot view draft policies, administrative logs, or audit workpapers.
  • Non-Repudiation of Attestations: Once an attestation is submitted, it is immutably recorded in the governance ledger. Employees cannot revoke or alter a completed attestation timestamp.
  • No Administrative or Governance Mutation: Employees cannot create policies, alter risk scores, approve exceptions, or modify compliance determinations.

5. What the System Does NOT Imply

Employees and managers must understand what policy attestation signifies:

Semantic Guardrails

  • Attestation $\neq$ Compliance: An employee's electronic acknowledgment confirms that the policy was made available and acknowledged by the employee. It does not certify that the employee or business process is continuously compliant.
  • Attestation $\neq$ Control Effectiveness: A 100% attestation rate on an information security policy proves effective policy distribution; it does not prove that underlying technical controls (e.g., firewall filtering or access termination) are effective.
  • Policy Published $\neq$ Employee Adherence: Having an active policy in /my-policies defines the mandatory organizational standard; adherence must be continuously validated through operational controls and supervision.

6. Where to Learn More

OrviQ Enterprise Governance, Risk & Compliance Platform