Skip to content

Your SharePoint site

What Certaria builds in SharePoint, what each container is for, and what is safe to change once it is there.

Audience: ISMS Admin.

Why this matters: SharePoint is the only part of Certaria most of your organisation ever touches. Administrators work in the model-driven app; everyone else reads policies and reports concerns on this site, and confirms what they have read on the Certaria card in Teams, needing nothing beyond your existing Microsoft 365 subscription.

It is also the part you are most likely to tidy up without realising what depends on it.

During onboarding you nominate a SharePoint site, and Certaria creates eight containers in it, plus one page. It creates them once and verifies them on every later run.

ContainerWhat it isWhat it is for
Policy MastersDocument libraryYour editable master documents. The root of this library is where a document becomes real. Administrators only; your people cannot open it
Document RepositoryDocument libraryThe approved PDF of each published document, which is what your people actually read. Built by Certaria, not by you
Published DocumentsListWhat staff read from, with each document’s reference and version. Confirmation happens on the Certaria card in Teams. Built by Certaria, not by you
AcknowledgementsListWho confirmed what, and when. Your audit trail
ConcernsListWhere staff report something
ExportsDocument librarySAR packs and other generated exports. Administrators only
Audit PackDocument libraryWhat you assemble for your auditor. Certaria does not fill it
EvidenceDocument libraryCollected evidence files

The page is ISMS Home (ISMSHome.aspx in Site Pages), a staff landing page that Certaria sets as the site’s home page. Your original home page is not edited or deleted: it stays in Site Pages, and one setting brings it back. The home page Certaria builds covers what is on it and how to make it yours.

Who can reach each of these is a separate decision and a longer answer. Who can see and do what covers it, including the two points an auditor will ask about.

The distinction that causes the most confusion

Section titled “The distinction that causes the most confusion”

Policy Masters holds the document you edit. Document Repository holds the PDF your people read.

Two libraries, two audiences. You work in Policy Masters, and your staff cannot open it at all. When you approve a document, Certaria freezes a PDF of it into Document Repository and builds the reading page that points at that PDF.

That separation is the product working. Your people are never shown a file that is mid-edit, and every confirmation is against a version Certaria can still produce.

Adopt a template covers that step, and Publish a document covers the procedure.

This is the question that actually gets asked, so here is the direct answer.

ChangeSafe?Why
Adding your own folders inside a libraryYesCertaria publishes from the root of Policy Masters. Other folders are yours, and a file inside one is not published
Moving a file between foldersYesCertaria matches on file name, not location
Adopting a template from the Certaria hubYesThis is the intended way to add a document
Renaming a fileNoCertaria matches on file name. A rename produces a second document record rather than updating the first
Renaming a library or listNoThe names above are what Certaria’s automations look for. Renaming one stops the automation that depends on it, silently
Deleting a file from Policy MastersAvoidThe document stops being published at the next run. Adopting the template again restores the file and re-links the record you already have
Adding columns to a listUsuallyCertaria ignores columns it does not know about. Do not remove or rename the ones it created
Adding your own navigation linksYesCertaria only checks for the four it added. Anything else on the left navigation is yours
Renaming a navigation linkNoCertaria finds its links by name. Rename one and the next run adds the original back, leaving two links to the same place
Editing the ISMS Home pageYesCertaria creates ISMSHome.aspx once and never edits it again. Anything you change stays changed
Choosing a different home pageYesYour original page is still in Site Pages. Select it there and choose Make homepage. Certaria will not change it back
Deleting ISMSHome.aspxAvoidThe next onboarding run treats it as missing, rebuilds the stock version and makes it the home page again. Your edits do not come back
Editing a PDF in Document RepositoryNoCertaria rebuilds it from the master. Edit the document in Policy Masters instead

Your policy library keeps version history because SharePoint turns it on by default, not because Certaria asks for it. It is worth knowing the difference: nothing in Certaria would restore it if it were switched off.

The default retains 500 major versions, which is what makes the recovery above possible. If your organisation has tightened version limits as a storage measure, check this library before you rely on it.

Certaria adds three entries to your site’s navigation when it builds the containers, two of them with a drop-down beneath:

EntryGoes to
DocumentsThe Published Documents list: everything approved and in force
Documents, then a category (Policies, Procedures, Guides, Plans, Registers, Reports, Templates)The same list, showing only that category
My Compliance, then My AcknowledgementsA person’s own confirmations, and only their own
My Compliance, then Required TrainingThe training that applies to your people, each requirement showing its audience
My Compliance, then Training RecordsCompleted training as read-only confirmations, each person’s own
Report a ConcernThe Concerns list

Every one of those points at a list rather than at a page. That is deliberate. Lists are what Certaria creates and checks on every run, so the navigation cannot end up pointing at something that is not there. The same check keeps a rebuild from adding a second copy of an entry that is already in place.

Onboarding creates one page, ISMS Home, and makes it the site’s home page, so the first thing staff see explains the site rather than SharePoint’s stock welcome banner. Top to bottom:

  • a dark hero naming your organisation, with one button to see what applies
  • Security notices, the news section you feed
  • What applies to you: the published documents list and the required training list, each embedded on the page so somebody can start reading without navigating anywhere first, with every training requirement showing its audience
  • What you have confirmed: each person’s own confirmations, theirs alone
  • the Report a concern band, one clear route in
  • Fast paths: three buttons for training, the Document Repository and contacting you
  • a footer carrying the Certaria mark, quiet links, your scope statement once it is set, and the copyright line

The page names all four kinds of document it fronts: policies, procedures, guides and plans all publish to the same list and are confirmed the same way. Comments are switched off on the page: an unmoderated comment thread on your security landing page serves nobody.

Certaria creates this page once and never edits it again. That is deliberate: the page is yours, and anything you change stays changed. The other side of the same coin is that Certaria cannot correct it either. If the page names the wrong person, or says “your organisation” because onboarding ran before you entered your organisation’s name, open the page, select Edit and fix the text like any other SharePoint page.

Your original home page still exists, untouched, in Site Pages. To go back to it, open Site contents, then Site Pages, select the page you want and choose Make homepage. Certaria will not change it back.

The page ships without imagery, deliberately: images have to live somewhere, and yours belong to you. The additions that repay the few minutes each:

  • Your own photography or an Image web part in the Who to ask band, to put a face to the role.
  • A site logo (Site information, then Change logo), which carries into the header of every page.

Certaria builds the home page at provisioning: a dark hero stating whose ISMS this is; Security notices; the published documents and required training lists; each person’s own confirmations; the Report a concern section; three Fast paths buttons for training, the Document Repository and contacting you; and a footer carrying the Certaria mark, quiet links and, once your scope statement is set, what this ISMS covers. It is a normal SharePoint page, so you can edit it, and Certaria will not overwrite your changes: the page is built only when it does not exist.

Security notices is yours to feed. It shows news posts from this site, newest first, and arrives with one seeded post explaining how the site works. To post one: open the home page, choose New, then News post, write it like a document, and select Post news. Use it for the things your people should hear about between documents: an active phishing theme, a newly published policy, a seasonal reminder. Staff can read notices and cannot author them.

Give each notice a picture that fits it, using the image control at the top of the post. The abstract Certaria artwork on the seeded post is the default look, there to say “this is an official notice” rather than to illustrate anything, and headings belong in the post title, never in the image itself.

Staff land on the ISMS Home page described above, and from there reach two things, both ordinary SharePoint:

  • Published Documents, where each approved document opens its own reading page: the frozen copy with its title, reference and version, and that person’s own acknowledgement state beneath it. Confirming happens on the Certaria card in Teams, which lists what they still owe and records exactly what they tick.
  • Report a concern, which writes to the Concerns list. The form asks for a headline, what happened, and the closest category in plain language; a screenshot or photo can be attached as evidence.

A confirmation made on the card is recorded in the register immediately. The person’s own copy on this site, under My Acknowledgements, follows within the hour, because the site is a read-only projection of the register rather than the record itself.

Concerns travel the same hourly road, in both directions. A new concern becomes an incident in your Hub within the hour, pre-classified from the category the reporter chose and noting any attached evidence, with a link back to the original report. As you work the incident, its progress writes back to the list, so the reporter watches the status move from New to Reviewing to Closed without anyone updating the list by hand.

SymptomCauseFix
A document record never appeared for a fileThe file is in a subfolder rather than the root of Policy Masters, or fewer than ten minutes have passedMove it to the root, or wait for the ten-minute sweep
Two document records for one fileThe file was renamed after its record was createdDelete the surplus Draft record. Copy and move freely; rename rarely
A document is Approved but staff cannot see itCertaria cannot find its file in the root of Policy MastersPut the file back in the root and let the next run rebuild the reading page
Nobody is asked to confirm a published documentThe daily reminder has not run yet, or the document is set not to ask for confirmationCheck the document asks for one, then wait for the next daily run
A template no longer looks cleanIt was edited where it satRestore it from Version history
The site still shows its original home page after onboardingPage creation is the one provisioning step allowed to fail without failing the runRe-run onboarding. The page is created only if it is missing, so nothing else is disturbed