> For the complete documentation index, see [llms.txt](https://docs.cyberally.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cyberally.com/vanta-onboarding.md).

# Vanta Onboarding

![Vanta onboarding](/files/ColvfJ92rsclN6d9DvOI)

## Welcome to Vanta!

Welcome! This guide is your roadmap for getting started with Vanta. Our goal is to take you from a brand-new account to a fully configured, automated compliance platform.

Vanta works by connecting to your company's tech stack to continuously monitor your security posture and automate evidence collection for audits. Following these steps in order will ensure a smooth and successful setup.

### The Vanta Setup Journey

1. **Set Up Your Company Information** (The First Step)
2. **Connect Your Systems** (The Foundation)
3. **Verify Your People and Assets** (The Internal Inventory)
4. **Manage Your Vendors** (The External Inventory)
5. **Establish Your Policies** (The Rules)
6. **Provide Your Evidence** (The Proof)
7. **Conduct Your Risk Assessment** (The Strategic Plan)
8. **Perform Access Reviews** (The Gatekeeping)
9. **Monitor and Remediate** (The Day-to-Day)
10. **Build Trust Externally** (The Payoff)

## Prerequisite: Grant Admin Access (If not under our MSP program)

Before you begin the setup process, it's essential to grant our team administrative access to your Vanta account. This allows us to guide you, troubleshoot issues, and ensure a smooth onboarding experience.

{% hint style="info" %}
**Note:** This step is only for clients who are not part of our full Managed Vanta Program. If you are a managed client, this has already been configured for you.
{% endhint %}

For instructions on designating us as an Admin user in Vanta, please refer to our detailed setup guide: [**Vanta Admin User Setup Guide**](https://docs.google.com/document/d/1DpviN8l3-fr1-r2td_jUrYHBCADrPxrMVFNtAzOCt4Y/edit?usp=drive_link).

## Step 1: Set Up Your Company Information

Before diving into integrations, let's ensure your company profile is complete. This information is used across the platform, including in your public-facing Trust Center and in reports.

![Company information settings](/files/e0QXHaoNjqopgcrcxiXI)

1. Navigate to the Settings page from the main menu on the left.
2. Select the Company > Information tab.
3. Fill out the key details:
   * **Display Name:** Your business name.
   * **Legal Name:** Your official business name.
   * **Website:** Your primary company URL.
   * **Company Logo:** Upload a high-resolution version of your logo. This will be used in your Trust Center and other branded assets.
   * **Description:** A brief, marketing-approved paragraph about what your company does.
4. Click **Update Information**. This simple step ensures a professional look and feel across the platform.

## Step 2: Connect Your Systems (The Most Important Step)

Vanta's automation is powered by integrations. Connecting your systems is the non-negotiable first step.

1. Navigate to the **Integrations** page from the main menu.
2. **Connect your Identity Provider first!** This is your source of truth for employees. Find and connect your provider (for example, **Google Workspace, Microsoft 365, Okta**). Be sure to **descope service accounts** (for example, <test-account@example.com>, <staging-user@example.com>) or unnecessary users from your connected identity provider.

![Integrations page](/files/wbhybqJ7DbPYGe6MCXyY)

3. Next, connect your primary **Cloud Provider** (for example, **AWS, Azure, GCP**).
4. Continue connecting other key systems from your tech stack, such as:
   * **Version Control** (for example, GitHub, GitLab)
   * **HRIS** (for example, Gusto, Rippling, Employment Hero)
   * **Device Management / MDM** (for example, Kandji, Jamf, Intune)

{% hint style="success" %}
**What Happens Next?** As you connect these systems, Vanta will begin fetching data in the background. This will start to automatically populate other areas of the platform.
{% endhint %}

For Vanta integration details across cloud, identity, and HR platforms, refer to the **Vanta Integrations Guide**. It offers step-by-step instructions, best practices, and troubleshooting for security and compliance. Access it here: [**Vanta Integrations Guide**](https://docs.google.com/document/d/1JS_xnYaNpMa9W8LhuQA93GogHpclkIrjVktUM0Ijel4/edit?usp=sharing).

## Step 3: Verify Your People and Assets

Now that Vanta is pulling in data, let's make sure your inventory is correct.

1. Go to the **Personnel** > **People** page. Does this list accurately reflect all of your current employees? It should match the user list from the Identity Provider you just connected. To assist with task assignment, create or import groups (for example, development team, executive team) based on your organisation and assign users to them. Additionally, please create a **separate group** specifically for **Cyber Ally**, and ensure **no tasks** are assigned to this group.

![People page](/files/eIkMdj5q4uS2KOjwLsBX)

2. On the **Access** page, verify that all accounts are assigned to an individual. If an account is not assigned to an individual, mark it as "Not a person." If the account is external or not within the company, tag it as "External user."

![Access page](/files/zJ29YBs2wwD6B9Iqqeje)

3. Go to the **Computers** page. If you connect a Device Management tool, you will see a list of employee computers as well as their computers compliance status.
4. Review these pages for completeness. This ensures Vanta is monitoring your entire organisation correctly.

For detailed information on personnel management, please check the [**Personnel Management Guide**](https://docs.google.com/document/d/1Eh8O6NM9OFoh17x0KKiub5x_oAOK99lllUSwlJVLsE0/edit?usp=drive_link). For computer-related matters, refer to the [**Computer Management Guide**](https://docs.google.com/document/d/1JX5XnaNsDG5KxVKy_ij11x4eo1RjJ6ElxdxoDjlqsw8/edit?usp=drive_link).

## Step 4: Manage Your Vendors

![Vendors page](/files/WtQDlZIQJOp9wBUtdYb6)

After inventorying your internal assets, the next step is to create a complete list of your third-party vendors.

1. Navigate to the **Vendors** page. Vanta will have automatically added some vendors based on your integrations.
2. Review the list for completeness. For any missing vendors, click **Add Vendor** and enter their name and website.
3. For each vendor, click on their name and assign a **Security Owner** and **Business Owner**: the internal person responsible for managing that vendor relationship. This is a critical step for accountability.

For a comprehensive understanding of Vanta's vendor management process, please consult the [**Vendor Management Process Guide**](https://docs.google.com/document/d/1C9AzoBhPVDqfQqC8D5TzGaXdWIP2E4psx8r6ptwJwGo/edit?usp=drive_link).

## Step 5: Establish Your Company Policies

![Policies page](/files/cGA0g4T9fPolqumbL40T)

Policies are the written rules of your security program. Vanta helps you manage them and track employee acceptance.

1. Navigate to the **Policies** page. You will see a list of policies Vanta requires for your chosen framework (for example, SOC 2).
2. Click on a required policy, such as **"Information Security Policy."**
3. You have two main options:
   * **Use a Vanta Template (Recommended):** Select "Start from a template," then carefully customise the content to match your company's practices.
   * **Use Your Own Document:** Upload your existing policy file or import it from Google Drive/Confluence.
4. Configure the **Owner**, **Approval Date**, and the **"Applies To"** employee group for the policy.
5. Click **Publish**. Vanta will automatically assign a task to all relevant employees to read and accept the policy.
6. Repeat for all required policies.

For a comprehensive understanding of policy management stages and protocols, consult the detailed [**Policy Management Guide**](https://docs.google.com/document/d/1QE6XolPk2uTN-KAP9movii2Jz5b1R6_-mERMb81wk-0/edit?usp=drive_link). It offers in-depth explanations, best practices, and crucial information for effective policy lifecycle navigation.

## Step 6: Upload Your Evidence Documents

![Documents page](/files/2bWWa0fazChcF8QuOncg)

While Vanta automates a lot, some evidence must be provided manually. The **Documents** page gives you a checklist of what's needed.

{% hint style="warning" %}
**Policies vs. Documents:** The **Policies** page is for employee-facing rules. The **Documents** page is for audit evidence files (like reports and certificates).
{% endhint %}

1. Navigate to the **Documents** page.
2. Click on a required document, such as **"Penetration Test Report."**
3. Click **"Add a document"** and choose your preferred method:
   * **Upload:** For static files like a PDF.
   * **Add URL:** To link to a document in SharePoint, your knowledge hub, etc.
   * **Import:** To link to a document in Google Drive or Confluence.
4. Fill in the document details (Owner, Date, etc.) and submit.
5. Work your way down the list, fulfilling each requirement.

For details on uploading documents and configuring system settings, refer to the [**Document Management Guide**](https://docs.google.com/document/d/1UjPr__ffwEHw8SoYRg8dK6YC90dK1wFH-mUTiR82dqA/edit?usp=drive_link).

## Step 7: Conduct Your Risk Assessment

![Risk page](/files/OKwpKg0cDirXiQN0K6ZI)

A formal risk assessment is a mandatory part of any compliance program. Vanta provides three ways to build your Risk Register.

### Overview of Risk Assessment Methods

* **Use Vanta's Templates:** Vanta will pre-populate your register with a comprehensive list of common risks. This is the fastest way to get started.
* **Import from a CSV:** If you already have a risk register in a spreadsheet, you can download Vanta's CSV template, format your data, and import it in bulk.
* **Add Risks Manually:** You can add company-specific risks one by one.

### The Process

1. Navigate to the **Risk** page and click **"Start risk assessment."**
2. Choose your preferred method to populate the register. For each risk in the Risk Register, you must:
   * **Assess** it by setting its Likelihood and Impact.
   * **Assign** a Risk Owner.
   * **Treat** the risk (usually by Mitigating it) and connect the **Vanta controls** that help reduce the risk.
3. Once all risks are assessed and treated, follow the prompts to formally **Approve** the assessment and generate the report.

The [**Risk Management Guide**](https://docs.google.com/document/d/1MHQH0O0XWPPlGlKGlZwB1FQR3bXqZYA5E8ixPR53thU/edit?usp=drive_link) details best practices for comprehensive risk assessment, including identification, analysis, evaluation, treatment, prioritisation, and mitigation. It covers qualitative and quantitative methods, continuous monitoring, and framework establishment for organisational resilience and compliance.

## Step 8: Perform User Access Reviews

![Access reviews](/files/VSqghkKfLh3QhJtRwlBy)

This is a periodic process to ensure users only have access to what they need. There are two methods to perform access reviews.

### Path A: Manual Review (Standard Process)

This is the standard workflow for all Vanta accounts. You will perform the review offline and upload the results as evidence.

1. **Export User Lists:** For each critical application (for example, Salesforce, AWS, your custom database), log in as an admin and export a complete list of users into a spreadsheet (CSV).
2. **Perform the Review Offline:** Assign a business owner to review each spreadsheet. They will go through the list and mark each user's access as "Approved" or "Revoke."
3. **Upload as Evidence:** Upload the completed, reviewed spreadsheet to the **Documents** page in Vanta. You will connect this file to the relevant access review control(s) to prove the review was completed.

### Path B: Automated Review (Premium Vanta Feature)

If your Vanta subscription includes the **Access Reviews module**, this process is streamlined within the platform.

1. Navigate to the **Access Reviews** page.
2. Click **"Start Review"** and select your integrated applications.
3. Vanta automatically assigns review tasks to the designated application owners.
4. Reviewers log in to Vanta and approve or revoke access for each user directly within the UI.
5. Once complete, Vanta automatically generates the final, audit-ready report as evidence.

For an in-depth understanding of the user access review process, refer to the [**User Access Review Guide**](https://docs.google.com/document/d/1ELSI8SDvTayAc-yUTzP8ODaUcDtvvbAChK7ecZ3Slis/edit?usp=drive_link).

## Step 9: Monitor Your Tests and Remediate Issues

![Tests page](/files/b1vchry9zoWTTasXV3aP)

The **Tests** page is your daily dashboard for compliance. It shows the real-time status of every security control Vanta is monitoring.

1. Navigate to the **Tests** page.
2. Use the filters to view **"Failing"** tests. These are the items that require your attention.
3. Click on a failing test to understand the issue and see a list of the specific resources (for example, users, computers, S3 buckets) that are out of compliance.
4. The "Remediation" steps will provide guidance on how to fix the issue.
5. Assign owners to controls and begin working with your team to resolve these findings.

## Step 10: Build Your Trust Center

![Trust Center](/files/VI56gpY8McB4o6prebrl)

Now that you've established your security posture, the Trust Center helps you share it with customers and prospects to accelerate sales cycles.

1. Navigate to **Customer Trust > Trust Center**.
2. Follow the setup wizard to:
   * Add your company logo and description.
   * Upload key security documents you want to share (like your SOC 2 report).
   * Configure an NDA if you want to gate access to sensitive documents.
3. **Publish** your Trust Center and add the link to your website's footer.

## Congratulations and Next Steps

Congratulations! By completing these steps, you have successfully set up your Vanta instance. You have moved from zero to a state of continuous, automated security and compliance monitoring.

Your ongoing tasks will primarily involve:

* Monitoring the **Tests** page for any new issues.
* Ensuring new employees complete their security checklists.
* Performing periodic reviews (like vendor assessments and access reviews) as prompted by Vanta.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cyberally.com/vanta-onboarding.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
