Skip to content

Onboarding and site setup

The three step wizard, what Certaria builds in your SharePoint site, and where your live policies are meant to live.

Audience: ISMS Admin. Run this once, with the same account that installed Certaria.

How long: about fifteen minutes, plus a minute or two of waiting.

Have to hand:

  • Company name, exactly as it should appear in policies and reports.
  • Your registered office address.
  • Your industry and approximate employee count.
  • The email address of your ISMS administrator.
  • Your ISMS scope statement, in one plain sentence. You can refine it later.
  • Your Cyber Essentials status, if you hold it.
  • The URL of the SharePoint site where your ISMS should live, for example https://contoso.sharepoint.com/sites/Certaria.

Company name, registered address, industry, ISMS administrator email and the scope statement are all required before the wizard will let you continue.

  1. Open the Certaria ISMS Management Hub app.

  2. On a fresh environment the Home screen tells you Certaria has not been configured in this environment yet. Select Open Certaria Onboarding. If that screen does not appear, open Certaria Onboarding directly from your apps list: both doors lead to the same place.

    The Certaria ISMS Management Hub home screen on an unconfigured environment, with an Open Certaria Onboarding button. The hub tells you plainly that nothing is configured yet, rather than showing you an empty dashboard.

  3. The Welcome screen summarises the three steps. Select Start setup.

    The Certaria Onboarding welcome screen, listing the three steps: Organisation, SharePoint and Templates, and Readiness Scan. Three steps, about fifteen minutes, and every step is safe to re-run.

  4. First launch setup runs for under a minute. It prepares environment settings and switches on Certaria’s workflows, then the wizard reloads itself.

Enter your company name, registered address, industry, approximate employee count, ISMS administrator email and scope statement, then record your Cyber Essentials status.

Step 1 of the wizard, showing the organisation fields and the Cyber Essentials question. Fields marked with an asterisk are required. Approximate employee count is the only one on this screen that is not.

Cyber Essentials is worth answering accurately. It covers aspects of 14 ISO 27001 Annex A controls, and answering Yes or In progress marks those 14 as Partially evidenced, so you are not asked to prove the same thing twice.

Select Continue.

Set your SharePoint site URL, save it, then start the environment preparation. Certaria verifies the site and builds your ISMS there.

This is the step that matters most later, so it is worth knowing what it creates. Wait for Environment is ready before moving on.

Step 2 of the wizard showing the Environment is ready confirmation. Preparation takes a couple of minutes. Continue only once you see this.

Eight containers: your ISMS Policies library with its Pending Applicability folder, the Published Policies and Policy Acknowledgements lists, Concerns, and three administrator-only libraries for ISMS Working, the Audit Pack and Evidence.

Your SharePoint site explains what each one is for and, more usefully, what is safe to change once it exists. One thing from it is worth knowing before you continue.

  1. Select Save and run Readiness Scan. It reads your Microsoft 365 security data and grades you against the Annex A controls. The wizard tells you this may take up to two minutes.
  2. Read the four result tiles: Fully evidenced, Partially evidenced, Manual evidence required, and Microsoft Secure Score.
  3. Optionally set the notification timings: which account posts Teams messages, the daily reminder hour, the weekly acknowledgement slot, and whether the daily incident check runs.

Step 3 after a scan, showing the four result tiles and the workflow notification timing fields. The first three tiles account for all 93 Annex A controls between them. Secure Score is Microsoft’s own number, carried through unchanged.

Select Continue.

The summary screen shows your organisation, your Power Apps licence status, your Cyber Essentials record and your scan results. It stays available as a status screen you can return to.

Select Finish setup. Certaria records onboarding as complete and the hub becomes your daily home.

Two things are worth doing immediately, because everything else depends on them:

  1. Set your access model. Certaria creates the containers; who can reach them is your decision and your auditor will ask about it.
  2. Import your people. A person with no linked user account receives no notification and appears in no reminder, silently.
SymptomCauseFix
The wizard shows a sign in screen after Start setupExpected. The wizard reloads itself after first launch setupSign in with the same account
Sign in opens a blank windowYour browser is blocking the Microsoft popupAllow popups for apps.powerapps.com and make.powerapps.com, then reload
Power Apps licence not detectedUsually accurate: the signed in account has no Power Apps licence of any kindAssign it in the Microsoft 365 admin centre, then re-check the licence from the wizard. It re-checks the licence only and leaves your scan results alone
Step 2 fails on the SharePoint URLThe site does not exist, or the account running the wizard cannot reach itConfirm the URL opens in a browser for that account
A workflow shows as Off afterwardsUsually a transient activation failureTurn it on in the solution’s cloud flows list. If it names a connection, sign that connection in first