Core workflows

Keep a live inventory of information assets

Track systems, data stores, devices and third-party services in one place — with owner, sensitivity and linked risks and controls.

6 min read · updated July 2026

Step-by-step

  1. 1

    Open Assets

    The assets page shows every asset by type, sensitivity and owner. Use filters to narrow to 'customer data' or 'SaaS'.

    Open Assets
  2. 2

    Import your existing list

    Import → CSV pulls in your existing spreadsheet or MDM export. Column names match the template — download it from the import dialog.

  3. 3

    Classify each asset

    Set the data classification (Public, Internal, Confidential, Restricted). This is what governs your encryption, access and retention policies.

  4. 4

    Link risks and controls

    Open an asset and use the Links panel to connect it to the risks it exposes and the controls that protect it. This gives you a full asset-risk-control graph auditors love.

What corporate buyers look for
  • "Do you maintain an inventory of assets that store or process our data?"
  • "How are assets classified for sensitivity?"
  • "Which of your subprocessors will access our data?"

What this workflow produces: The asset inventory export plus the subprocessors list feeds directly into most DPAs and vendor security questionnaires.

FAQ

Do I need to inventory every laptop?

For ISO 27001 you need to know which classes of device store what data. If MDM already covers device-level inventory, reference that system as the source of truth.

What about subprocessors?

Add subprocessors as asset type 'Third-party service'. The Trust Center automatically shows them under Subprocessors.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation