The left menu at a glance
A one-page map of the left sidebar: every group in the order it appears and every item it holds, each linking to its own chapter — so you can find any screen, then read it in depth.
The left sidebar is how you move around Aegis. Its items are gathered into groups, and the groups are ordered to follow the shape of a compliance programme: Governance first (what you are trying to achieve and who oversees it), then Risk (what could go wrong), then Compliance (the frameworks, documents and evidence that show you are in control). After those three core groups come the supporting areas — audit, documents, privacy, incidents, assets, AI, reporting and administration.
Two things change what you actually see: your licence tier (the bundle of modules your organisation has bought) hides modules you do not have, and your role hides links that need a higher permission. So your menu is personal to you — a colleague's may be longer or shorter. From here on the guide takes each item below in this exact order.
Governance
Set direction and keep oversight of the whole programme.
- Dashboard — your landing page: headline figures for compliance, risks, policies and vendors.
- Getting Started — the guided checklist for a new workspace.
- Analytics — trends and breakdowns across your programme.
- Roadmap — the compliance timeline of planned and derived milestones.
- Governance Bodies — boards and committees, meeting minutes and the actions they raise.
- Security Processes — your active security-process definitions and their follow-up.
- Security Standards — the technical baseline (such as encryption) linked to policies.
- Security Awareness — staff training and phishing-style campaigns.
Risk
Track what could go wrong, including third-party risk and early-warning signals.
- Risks — the risk register: identify, score and treat risks.
- Threat Actors — the groups and actors a risk may come from.
- Exceptions Register — where a control is knowingly not met, with a reason and an owner.
- Vendors — third-party and supply-chain risk: onboard and risk-rate suppliers.
- Anomalies — automatically flagged unusual activity, as a risk signal.
Compliance
The compliance core: frameworks, the policies and procedures that implement them, the evidence that proves they work, and the framework-specific surfaces.
- Control Measures — the frameworks you track and your progress against each.
- Policies — draft, review and approve organisational policies.
- Procedures — the step-by-step processes that put policies into practice.
- Evidence — the Evidence Locker: the proof that a control works.
- Control Monitoring — track whether controls stay effective over time.
- Control Mapping — map one control across several frameworks and remove duplicate work.
- CyFun Maturity — the CyFun framework's maturity view.
- Questionnaires — security and compliance questionnaires you send or answer.
- Audit Readiness — check how prepared you are before a real audit.
- DORA — the framework surface for the Digital Operational Resilience Act.
- EU AI Act — the framework surface for the EU AI Act, including the AI system inventory.
- Regulatory Alerts — incoming regulatory news to triage.
- Regulatory Changes — the changes you act on.
Audit
Running and recording audits.
- Mock Audit — a rehearsal audit to find gaps before the real one.
- Benchmarking — compare your posture against peers.
- Audits — scoped audit engagements and their planning.
- Audit Log — the immutable record of who did what and when.
Documents
Reading and working together on published documents.
- Documents — the documents staff are expected to read.
- Action Center — comments, review threads and the items waiting on you.
Privacy & Whistleblowing
The data-subject and individual-rights surfaces.
- GDPR — data-subject requests, transfers and privacy records.
- Whistleblowing — the case list for protected reports.
- Report a Concern — the intake form any signed-in user can use to raise a concern.
Security Incidents
Handling incidents from detection to regulator reporting.
- Incidents — log, triage and resolve security incidents.
- Reporting — prepare the reports a regulator may require.
- Auto-Incident Rules — rules that open an incident automatically when a condition is met.
Assets (CMDB)
Your inventory of what you have to protect, including the software bill of materials.
- CMDB — the machine and device register.
- Software — the software asset register.
- Information Assets — the information-asset register.
- CMDB Services — internal services you run.
- External Services — third-party services you depend on.
- SBOM — the software bill of materials, a list of the components inside your software.
AI
The shared AI layer that assists across modules — a person always reviews and decides.
- AI Dashboard — the assistant and where AI activity is summarised.
- AI Agents — the task-running agents.
- Playbooks — repeatable, guided response procedures.
Reporting
Turning your data into documents for others.
- Reports — generated operational reports.
- Board Reports — board-level summary decks.
Administration
Operational configuration, integrations and tenant settings. These links need Manager or Admin.
- Workflows — automate routine steps across modules.
- HR Integrations — the HR integration for joiners and leavers.
- Connectors — connect Aegis to email and other systems.
- Settings — workspace configuration.
- Document Template — the house style applied to generated documents.
- Trust Center — your public trust page.
- API Keys — programmatic access keys.
- Webhooks — outbound event notifications to other systems.
Where this connects
From here the guide follows this same order, one screen at a time. Start with Dashboard, or jump to any chapter above. For what each role can see and do across these screens, see What each role can do.