Skip to main content

Have something to say?

Tell us how we could make the product more useful to you.

Proactive Integration Scoping Guidance

Customers over-configured integrations (e.g., connecting every cloud account/project) when a smaller footprint would have sufficed, and felt the team should have pushed back more firmly during setup. Proposed Solutions: Build proactive scoping guidance into the integration setup flow. Recommend a minimum viable evidence footprint (e.g., one cloud account/one project) by default. Prompt users with a warning or confirmation step when configuration exceeds the recommended minimum. Acceptance Criteria: Setup flow displays a recommended minimum integration scope before configuration. Users attempting to exceed the recommended scope receive a warning/confirmation prompt. Documentation/in-app guidance explains why a minimal footprint is typically sufficient.

Shreya Yadav2 months ago

Pass-Guarantee SLA Improvement

The pass-guarantee's turnaround time (up to 10 working days) made it effectively unusable in practice, since customers could pass the relevant audit stage before the guarantee review was completed. Proposed Solutions: Surface the turnaround lead time clearly at sign-up and within the app. Display a booking deadline relative to the customer's audit date. Explore shortening the turnaround time or adding deadline reminder notifications. Acceptance Criteria: Turnaround time for the pass-guarantee is displayed at sign-up and in-app before booking. Users see a calculated booking deadline based on their audit date. Reminder notifications are sent to users approaching their booking deadline.

Shreya Yadav2 months ago

Realistic, Scoping-Based Timeline Estimates

Recommended project timelines were based on best-case scenarios rather than the customer's actual scope, leading to unrealistic expectations and excessive workload for customers trying to meet the estimated deadline. Proposed Solutions: Generate timeline estimates from a scoping/maturity assessment rather than best-case anecdotes. Factor in cross-team dependencies (e.g., IT availability) into the estimate. Present a realistic range (not a single best-case number) upfront during sign-up/scoping. Acceptance Criteria: Timeline estimates are generated based on assessment inputs specific to the customer, not a fixed best-case figure. Cross-team dependency factors are included as inputs to the estimate. Customers are shown a range rather than a single-point estimate before committing to a timeline.

Shreya Yadav2 months ago

Filtering and Focus/"My View" Modes

Customers found it difficult to focus on relevant work, wanting to filter out cross-standard mappings and see only their own tasks, evidence folders, or a single standard at a time. Proposed Solutions: Add filtering by task, control, evidence status, or standard. Introduce a "my view" mode that hides items not assigned to or relevant to the current user. Allow users to toggle visibility of cross-standard mappings. Acceptance Criteria: Users can apply filters by task, control, evidence status, and standard. A "my view" option is available that limits the display to the user's own items. Cross-standard mappings can be hidden or shown via a user-controlled toggle.

Shreya Yadav2 months ago

Policy Versioning and Sync

The policy module does not track or version externally-maintained policies, forcing customers to re-upload an entire new document for even minor changes rather than editing in place. Proposed Solutions: Add version history tracking for uploaded policy documents. Support in-place editing of uploaded policies. Build a sync/update mechanism for policies maintained outside the platform. Acceptance Criteria: Users can view version history for any uploaded policy. Users can edit an existing policy without re-uploading the full document. Changes to an externally-maintained policy can be synced/updated without starting from scratch.

Shreya Yadav2 months ago

Navigation UX Regression Review

A prior major platform upgrade made navigation more difficult, with customers reporting that previously simple workflows now require different, less intuitive paths. Proposed Solutions: Conduct a structured UX audit comparing pre- and post-upgrade navigation flows. Run usability testing on key navigation paths before future major releases ship. Address identified regressions in a follow-up release. Acceptance Criteria: A documented audit identifies specific navigation regressions introduced in the last major upgrade. Usability testing is completed and signed off before the next major release ships. Key workflows previously flagged as harder to navigate are validated as improved via user testing.

Shreya Yadav2 months ago

Better Integration Handling for IaC/Legacy Environments

Customers using infrastructure-as-code (e.g., Terraform) experienced repetitive findings and slow feedback loops, since changes required a code change followed by waiting for a fixed weekly re-scan cycle. Proposed Solutions: Deduplicate repetitive findings across scans. Support on-demand/manual re-scan triggers instead of relying solely on fixed weekly cycles. Allow scoping of integrations down to a single cloud account or project. Acceptance Criteria: Repeated findings from the same underlying issue are grouped or deduplicated in the UI. Users can trigger a manual re-scan on demand rather than waiting for the next scheduled cycle. Integration setup allows selecting a specific account/project scope rather than an entire environment.

Shreya Yadav2 months ago

Maturity-Aware Onboarding Path

Experienced or already-compliant customers found the platform over-engineered, with many guided tasks feeling redundant given their existing compliance frameworks. Proposed Solutions: Add a branching onboarding flow that asks whether the customer is starting from scratch or already has a framework/certification history. Allow existing evidence or AI-generated outputs to pre-populate a slimmed-down task list for experienced customers. Collapse redundant guided tasks into consolidated steps where possible. Acceptance Criteria: New customers select their starting profile (from-scratch vs. existing framework) during onboarding. Customers with existing frameworks see a reduced task list compared to first-time customers. Redundant tasks identified in feedback are consolidated or removed for the "existing framework" path.

Shreya Yadav2 months ago

Simplified, Guided Evidence Workflow

Customers found the evidence preparation and upload process more complex and time-consuming than necessary, particularly the step where evidence is packaged for the auditor. This was the single biggest driver of a customer abandoning the platform mid-project in favor of a manual system (folders + spreadsheet). Proposed Solutions: Introduce bulk upload and drag-and-drop support for evidence files. Organize evidence storage per-control/clause to mirror how customers naturally structure their files. Simplify the evidence-to-auditor hand-off step to reduce manual preparation work. Acceptance Criteria: Users can upload multiple evidence files at once via drag-and-drop. Evidence is automatically associated with the correct control/clause folder structure. The auditor hand-off package can be generated without manual reformatting by the user. Time-to-complete for evidence upload/hand-off is measurably reduced in user testing versus the current flow.

Shreya Yadav2 months ago

CIS Benchmark integration (Level 1 and Level 2)

Customers already using CIS Benchmarks (Level 1 and Level 2) via other security tools want to see those standards reflected in OCC. Currently OCC supports frameworks like Cyber Essentials, ISO 27001, and SOC 2, but does not map to CIS Benchmarks. Customers running CIS Level 1 hardening against Microsoft environments need OCC to either import CIS results or natively support CIS controls so everything is in one place. Proposed Solution: 1. Add CIS Benchmark Level 1 and Level 2 as supported standards in the Standards module. 2. Map CIS controls to existing OCC controls where overlap exists (e.g. CIS Level 1 MFA requirements β†’ existing MFA controls under Cyber Essentials / ISO 27001). 3. Support importing CIS scan results from third-party tools (e.g. CIS-CAT, Microsoft Secure Score) to auto-populate detection and compliance status. 4. Include CIS controls in the cross-mapping view alongside other frameworks. Acceptance Criteria: 1. CIS Level 1 and Level 2 are available as standards in the Standards module. 2. CIS controls are cross-mapped to overlapping controls in other frameworks. 3. Third-party CIS scan results can be imported. 4. CIS controls appear in the cross-mapping view. 5. Detections from CIS scans create tasks and update compliance posture.

Shreya Yadav3 months ago

Configurable email routing for system-generated notifications

System-generated emails (vendor questionnaire reminders, task assignments, scan results, etc.) currently go to a fixed recipient. Customers β€” especially MSPs managing multiple clients β€” need to control which email address receives which type of notification. A reseller may want vendor questionnaire emails routed to the client's compliance officer, while scan alerts go to their own SOC team. Proposed Solution: 1. Add a notification routing configuration in Settings where the admin can define recipient email addresses per notification type (e.g. scan results β†’ soc@company.com, vendor questionnaires β†’ compliance@client.com). 2. Support multiple recipients per notification type. 3. Allow per-client overrides for reseller/MSP accounts managing multiple orgs. 4. Include a test email function so admins can verify routing before going live. Acceptance Criteria: 1. Admin can configure recipient email addresses per notification type. 2. Multiple recipients are supported per type. 3. Reseller accounts can set per-client overrides. 4. A test email function is available. 5. Changes take effect immediately without requiring a platform restart.

Shreya Yadav3 months ago

Exploit categorisation and targeted CVE visibility

The pen testing tool currently shows pass/fail outcomes without surfacing which specific exploits or attack vectors were tested. Customers with security expertise want to know exactly what the tool probed for β€” which CVEs, which OWASP categories, which attack techniques β€” so they can assess the depth of coverage and map findings to their own vulnerability management processes. Proposed Solution: 1. For each pen test finding, display the specific exploit or CVE targeted (e.g. CVE-2024-XXXX). 2. Categorise findings by attack vector or framework (OWASP Top 10, MITRE ATT&CK technique, CWE). 3. Provide a test coverage summary showing which exploit categories were tested and which were out of scope. 4. Allow filtering and grouping of results by exploit category, severity, and CVE. Acceptance Criteria: 1. Each finding includes the targeted CVE or exploit identifier. 2. Findings are categorised by OWASP / MITRE ATT&CK / CWE. 3. A coverage summary shows tested vs out-of-scope categories. 4. Results can be filtered and grouped by exploit category and severity.

Shreya Yadav3 months ago

SharePoint and Google Workspace sync with OCC as source of truth

Customers want their employees to access compliance documents (policies, procedures, etc.) through their existing document platforms (SharePoint, Google Workspace) without manually exporting and uploading files each time a document is updated in OCC. Currently there is no sync mechanism, meaning OCC and SharePoint/Drive can drift out of sync, and employees may be reading outdated versions. Proposed Solution: 1. Introduce a one-way sync from OCC to SharePoint and/or Google Workspace β€” OCC is the source of truth, the external platform is a read-only mirror. 2. When a document is published or updated in OCC, it automatically pushes the latest version to a configurable SharePoint library or Google Drive folder. 3. Synced documents should be marked as read-only in the target platform to prevent employees from editing them outside OCC. 4. Sync status and last-synced timestamp should be visible on the document detail in OCC. Acceptance Criteria: 1. Published documents auto-sync to a configured SharePoint library or Google Drive folder. 2. Synced documents are read-only in the target platform. 3. Document updates in OCC trigger a re-sync. 4. Sync status and timestamp are visible per document in OCC. 5. Sync failures surface an error with retry option.

Shreya Yadav3 months ago

Admin notification for excluded service accounts and CA policy impact

When OneClickComply deploys a service account into a customer's tenant, that account may be excluded from Conditional Access policies. The admin is not proactively informed about this exclusion, which creates a blind spot β€” they may not realise their CA policies don't apply to the OCC service account. Similarly, if the tenant has security defaults or CA configurations that conflict with OCC's requirements, there is no upfront communication about it. Proposed Solution: 1. During or immediately after integration setup, display a clear notification to the admin listing any CA policies the OCC service account is excluded from. 2. If the tenant has security defaults enabled that may conflict with OCC, surface a warning with guidance on what to review or adjust. 3. Include this information in the post-setup email and make it accessible from the integration side panel under a 'Security notes' or 'Configuration notices' section. 4. If CA policy exclusions change on subsequent scans, notify the admin of the change. Acceptance Criteria: 1. Admin is shown which CA policies the OCC service account is excluded from during or after setup. 2. Conflicting security defaults trigger a visible warning with remediation guidance. 3. Information is accessible from the integration side panel post-setup. 4. Changes to CA exclusions on subsequent scans generate a notification.

Shreya Yadav3 months ago

Automated remediation with failure feedback

Running remediation tasks manually for each detection across each standard is extremely slow and labour-intensive. When a remediation script fails, the error feedback is either absent or too technical for the admin to act on. Customers want a way to trigger all remediations in bulk and get clear, actionable feedback when something fails, rather than clicking through each one individually. Proposed Solution: 1. Add a 'Run all remediations' bulk action at the standard level (and optionally at the integration level) that queues and executes all available remediation scripts in sequence. 2. For each script that fails, surface a plain-language error message with a suggested next step (e.g. 'MFA enforcement script failed β€” try rerunning via Azure CLI or check service account permissions'). 3. Provide a summary view after the bulk run: X succeeded, Y failed, Z skipped (already compliant). 4. Allow the customer to retry individual failures from the summary without re-running the entire batch. Acceptance Criteria: 1. User can trigger all remediations for a standard or integration in a single action. 2. Each failed script shows a plain-language error with a suggested resolution. 3. A post-run summary shows success/failure/skip counts. 4. Individual failures can be retried from the summary. 5. Already-compliant items are skipped and labelled as such.

Shreya Yadav3 months ago

Reseller / multi-tenant management

Resellers and MSPs managing multiple client environments have no way to operate from a single parent account. They currently need separate logins and billing relationships for each client org, making it impractical to scale across their client base. There is no hierarchical account structure, no consolidated billing, and no per-user pricing model suited to reseller economics. Proposed Solution: Introduce a reseller/MSP tier with: 1. A parent account that can provision and manage child (client) organisations from a single dashboard. 2. Role-based access scoping β€” reseller admins can switch between client orgs without separate credentials. 3. Consolidated billing across all child orgs with per-user or per-org pricing. 4. Client-level isolation β€” each child org's data, users, and configurations are fully separated. 5. Optional white-labelling so the reseller can present the platform under their own brand. Acceptance Criteria: 1. A reseller can create and manage multiple client orgs from one parent account. 2. Switching between client orgs does not require separate login. 3. Billing is consolidated under the parent account. 4. Client data is fully isolated between orgs. 5. Per-user pricing is configurable at the reseller tier.

Shreya Yadav3 months ago