← All resources
Guide3 min read

Set up your first workspace

What to connect, in what order, and what the agents have finished by the end of your first week.

A workspace starts at zero: no evidence, no policies, no measured coverage. This guide is the shortest path out of that. It covers what to connect, in what order, and what the agents have finished by the end of your first week.

Before you open the workspace

You need three things, and none of them is a compliance hire: the frameworks you are aiming at, an administrator on each system you want read, and one person who can approve what the agents produce.

  • Frameworks. Zero2Do ships 12, from SOC 2 and ISO 27001 to HIPAA, GDPR and PCI DSS. That is 1,054 controls in total. Pick the one you are being asked for; add the rest later.
  • Admin access. Cloud accounts, code hosting and your identity provider. Read-only scopes are enough, and there is nothing to install.
  • An approver. Someone who can say yes to a policy. The agents do the drafting; a person still signs.

Step 1: Pick your frameworks

Choosing a framework loads its controls and their cross-mappings at the same time. Those 422 mappings are the reason the second framework costs a fraction of the first: an access control tested once for SOC 2 already answers its ISO 27001 and HIPAA equivalents, and the coverage shows up in both places.

Step 2: Connect the systems you already run

Connect the noisiest system first. That is usually the cloud account. Credentials are encrypted at rest, scopes stay read-only, and the first collection run starts as soon as the connection is made rather than waiting for the rest.

If a system cannot be connected yet, leave it. Coverage is measured against what the agents can actually see, so an honest partial number on day one beats a complete one you had to assert by hand.

Step 3: Let the first heartbeat run

The agents work on a schedule rather than on request. One heartbeat pulls configuration and access records out of your systems, drafts the policies your frameworks require, has a second agent review each draft, runs the control tests that can be automated, and ranks what is still missing.

Every action is logged with what changed and why, so by the time you look at the workspace the question is not what should we do but is this right.

Step 4: Work your approval queue

Each heartbeat ends in a short queue of judgments only you can make: approve a drafted policy, confirm an exception, answer a question about how your team actually works. The approvals are recorded as audit trail. There is no separate spreadsheet and no second system of record.

What week one looks like

  • Day 1. Systems connected, first collection run finished, real coverage on the board instead of an estimate.
  • Day 3. Policies drafted against your environment and waiting for your approval; the acknowledgment queue is out to your team.
  • Day 7. Control tests have run at least once, gaps are ranked with the work the agents already did attached, and the audit room is filling up by control.

Where to go next

Read the evidence guide for what your auditor will ask to see, or how it works for the three moves behind all of this.