- Documentation
- Set up
Your SharePoint site
What Certaria builds in SharePoint, what each container is for, and what is safe to change once it is there.
Audience: ISMS Admin.
Why this matters: SharePoint is the only part of Certaria most of your organisation ever touches. Administrators work in the model-driven app; everyone else reads policies, confirms them and reports concerns on this site, needing nothing beyond your existing Microsoft 365 subscription.
It is also the part you are most likely to tidy up without realising what depends on it.
What Certaria builds
Section titled “What Certaria builds”During onboarding you nominate a SharePoint site, and Certaria creates eight containers in it. It creates them once and verifies them on every later run.
| Container | What it is | What it is for |
|---|---|---|
| ISMS Policies | Document library | Your live policies. The root of this library is where a policy becomes real. |
Pending Applicability | Folder inside that library | Certaria’s 34 unpersonalised templates, waiting on your applicability decisions |
| Published Policies | List | What staff read and confirm from. Built by Certaria, not by you |
| Policy Acknowledgements | List | Who confirmed what, and when. Your audit trail |
| Concerns | List | Where staff report something |
| ISMS Working | Document library | Drafts and revisions in progress |
| Audit Pack | Document library | What you assemble for your auditor. Certaria does not fill it |
| Evidence | Document library | Collected evidence files |
Who can reach each of these is a separate decision and a longer answer. Who can see and do what covers it, including the two points an auditor will ask about.
The distinction that causes the most confusion
Section titled “The distinction that causes the most confusion”ISMS Policies is a library. Its root holds your live policies. Pending Applicability is a folder inside it holding templates you have not adopted.
A file in Pending Applicability is not a policy, and Certaria refuses to publish one. That refusal is the product working: publishing an unpersonalised template would put a document full of placeholders in front of your whole organisation and collect confirmations against it, which is worse at audit than having no confirmations at all.
The policy templates covers adoption, and Publish a policy covers the procedure.
What is safe to change
Section titled “What is safe to change”This is the question that actually gets asked, so here is the direct answer.
| Change | Safe? | Why |
|---|---|---|
| Adding your own folders inside a library | Yes | Certaria looks at the library root and at Pending Applicability. Other folders are yours |
| Moving a file between folders | Yes | Certaria matches on file name, not location |
Copying a template out of Pending Applicability | Yes | This is the intended way to adopt one |
| Renaming a file | No | Certaria matches on file name. A rename produces a second document record rather than updating the first |
| Renaming a library or list | No | The names above are what Certaria’s automations look for. Renaming one stops the automation that depends on it, silently |
Deleting Pending Applicability | Avoid | You lose the templates for controls you have not yet adopted. Nothing else breaks |
| Adding columns to a list | Usually | Certaria ignores columns it does not know about. Do not remove or rename the ones it created |
| Editing a template where it sits | No | See below |
Versioning
Section titled “Versioning”Your policy library keeps version history because SharePoint turns it on by default, not because Certaria asks for it. It is worth knowing the difference: nothing in Certaria would restore it if it were switched off.
The default retains 500 major versions, which is what makes the recovery above possible. If your organisation has tightened version limits as a storage measure, check this library before you rely on it.
What staff see
Section titled “What staff see”Staff reach two things, and both are ordinary SharePoint:
- Published Policies, where each approved document has an Acknowledge link beside it. Selecting it records their confirmation against that specific version.
- Report a concern, which writes to the Concerns list.
Confirmations are read into the register hourly, so a confirmation made now is reflected within the hour rather than instantly. That delay is normal and is the usual explanation for someone saying they confirmed a policy but are still being reminded.
Common failure modes
Section titled “Common failure modes”| Symptom | Cause | Fix |
|---|---|---|
| A document record never appeared for a file | The file is in Pending Applicability, or fewer than sixty minutes have passed | Copy it to the library root, or wait for the hourly run |
| Two document records for one file | The file was renamed after its record was created | Delete the surplus Draft record. Copy and move freely; rename rarely |
| A policy is Approved but staff cannot see it | Its file is still in Pending Applicability | Copy it to the root and let the next run correct the link |
| The Acknowledge link is missing | The column and its formatting were not provisioned on this site | Re-run onboarding, which verifies rather than duplicates |
| A template no longer looks clean | It was edited where it sat | Restore it from Version history |
- Who can see and do what, the permissions behind the table above
- Publish a policy, the workflow that uses all of this
- What Certaria asks of you, the page written for everyone else