Overview
How the Noru app is organized and where to start inside the product.
Overview
Dashboard (/)
The dashboard is the operating summary for the active organization. It combines framework progress, controls, policies, asset counts, personnel posture, risks, findings, data-source state, internal audit, and trust-page publication into a single starting point. Privacy customers see the privacy operating overview, which is documented under Privacy.
Dashboard figures are read models of the underlying registers. Use them to find the next problem, then open the source page to understand and correct it. A dashboard percentage is not itself audit evidence.
The quickest way to make the product useful is to complete a minimal baseline:
- Policies: short, approved policies with acknowledgement history.
- Controls: owned controls with an evidence path.
- Assets: an owner-backed inventory of in-scope systems.
- Personnel: who’s in scope, training, and access/accountability.
- Risks: a small risk register you actually review.
Then connect data sources. Automated evidence and findings are valuable only after owners have reviewed the scope, mappings, and exceptions.
A durable operating rhythm
- Weekly: triage new findings, overdue work, personnel inconsistencies, and privacy review items.
- Monthly: review unmapped or stale evidence, unowned assets, vendor changes, and expiring certificates.
- Quarterly: review risks, critical vendors, trust-center content, framework scope, and control coverage.
- At least annually and on material change: review policies, personnel access, privacy processing records, internal audit scope, and management acceptance of residual risk.
Cadence depends on your risk profile and obligations; these are operational starting points, not legal rules.
Where things live
Use this as the mental map from UI → docs:
- Controls:
/controls→ Controls - Assets:
/assets→ Assets - Evidence Vault:
/evidence-vault→ Evidence Vault - Policies:
/policies→ Policies - Security:
/security/certificates,/security/findings→ Security - Risk Management:
/risk/register,/risk/reports→ Risk Management - Vendors:
/vendors/register,/vendors/questionnaires→ Vendors - Personnel:
/personnel/directory,/personnel/awareness→ Personnel - Audit:
/audit/*→ Audit - Privacy:
/privacy/*→ Privacy - Data Sources:
/data-sources→ Data Sources - Trust Center:
/trust-center→ Trust Center - Settings:
/settings→ Settings - Organization setup and selection:
/org/new,/org/select→ Organizations - Tasks:
/tasks→ Tasks - Cortex:
/cortex→ Cortex
The legacy /personnel/[id] and /evidence-vault/[id] routes redirect to their current directory-based
experiences. See Page reference for redirects and supporting pages.