6
6clicks Roadmap & Feature Requests
6
6clicks Roadmap & Feature Requests

Create a Post

Feature Name
Description (optional)
Powered by Noora
2
Add help text to looped question + symbol

Recommend addition of "Add More" or "Click Here to Add" alongside the + symbol for Looped Questions.

Currently it's not very clear that the user needs to click on the + symbol and instructions need to be added to the description field.
These instructions can disappear/may not always be visible depending on the amount of information entered by the respondent.

0
3
Hailey Evidence Validation in Custom Registers
In progress this quarter

Hailey's evidence validation capability is being extended into the Custom Registers architecture, starting with the Tests and Evidence registers. With richer context available -- test definitions, linked controls, framework mappings, and connected organisational data -- Hailey can validate evidence the way an experienced auditor would, not just check that something was submitted.

The capability is designed around three personas: control owners who define requirements, evidence submitters who respond to tasks, and evaluators who review submissions.

Key Components:

  • Validation Guide Generation: When a test is created, Hailey automatically generates a guide defining what valid evidence looks like for that context. Guides are editable by the control owner to accommodate organisation-specific requirements.
  • Submitter Experience: Submitters see the validation guide before uploading, can ask Hailey plain-language questions about what to provide, and receive specific feedback on any gaps before submission is confirmed. Iterative rounds are supported.
  • Auditable Override: If a submitter believes their evidence is valid despite Hailey's assessment, they can override with a written explanation -- creating a record visible to the evaluator.
  • Evaluator Experience: Evaluators receive submissions with Hailey's full validation history attached, including any overrides and the submitter's rationale.
  • Knowledge Graph-Powered Validation: Hailey reasons across linked organisational data -- asset registers, system inventories, existing evidence -- to catch discrepancies that a document-only review would miss.
  • Manual and Automated Test Modes: Automated tests are validated through integrations with no task required. Manual tests use the task workflow. Both surface validation status on the test record.

Benefits:

  • Eliminates the evidence back-and-forth loop -- submitters get clear guidance upfront, evaluators receive pre-validated submissions.
  • Validation uses linked organisational context, not just the submitted document, catching gaps that would otherwise reach the reviewer.
  • Full audit trail across every submission round, override, and automated validation result.
  • Works across file uploads, written descriptions, and pasted content -- no submission format is treated as second-class.

Example use case:

A systems administrator is assigned a task to provide evidence for a quarterly privileged access review. They ask Hailey what to submit and receive specific guidance. They upload a PAM export -- Hailey flags that it covers 47 accounts but the linked asset register shows 112 systems in scope. The administrator uploads a second export to address the gap. Hailey confirms coverage and the task is submitted. The evaluator receives the submission with the full validation history attached and can review with confidence, without performing a manual first-pass quality check.

1
3
Hailey-assisted Mappings in Custom Registers
In progress this quarter

Introduce a richer, more informative way to view and act on linked data across custom registers. This work replaces the current pill-based display with card-style linked data views and introduces Hailey-assisted mapping recommendations that proactively suggest relevant linkages based on a register item's data and context without requiring users to manually trigger or configure anything.

Key Components:

  • A linked data presentation component replacing the current pill-based display with card-style views that surface related object context at a glance, shown in context on detail screens (e.g. right-hand panel on a control detail screen).
  • Hailey-assisted mapping recommendations that analyse a register item's data, custom fields, and metadata and suggest relevant linkages, surfaced automatically in context without requiring manual triggering
  • Confidence-rated suggestions allowing users to review, accept, or reject individual recommendations, with the option to bulk-accept high-confidence mappings

Benefits:

  • Gives users richer at-a-glance context on how records relate to each other, reducing the need to navigate away to understand linkages
  • Reduces manual effort in identifying and creating relevant linkages across the platform
  • Keeps users in control by presenting AI suggestions for review rather than automating linkages silently
  • Lays the groundwork for downstream capabilities including compliance posture, gap analysis, and evidence validation enrichment that depend on reliable, well-structured linkage data

Example Use Case: A control owner is reviewing a control for MFA configuration. Rather than manually hunting for relevant evidence and deciding which tests it applies to, Hailey analyses the available evidence -- an exported Azure AD report confirming MFA enforcement across all privileged accounts -- and recommends linking it to the relevant test. The control owner reviews the recommendation and confirms the linkage. Related objects are displayed in a clear card-style panel alongside the control, giving immediate context without navigating away from the screen.

1
3
Controls Register: Built on Custom Registers
In progress this quarter

Controls are the central object in 6clicks' compliance data model -- everything connects to and from them: evidence, tests, tasks, framework provisions, assets, and systems. This feature rebuilds the Controls module on the same Custom Registers architecture used across the platform, placing controls at the heart of a connected compliance data model and unlocking capabilities that were not possible with the legacy module.

Teams can migrate on their own timeline. The legacy Controls module remains fully functional during the transition, and migration is opt-in and customer-controlled.

Key Components:

  • Controls Register: A dedicated out-of-the-box register for creating and managing controls, with all standard fields preserved from the legacy module. Control sets allow controls to be organised, grouped, and reused across frameworks and programs.
  • Many-to-Many Linking: Controls link to evidence, tests, tasks, and framework provisions in any direction. A single control can satisfy multiple provisions across multiple frameworks simultaneously, and compliance status assessed on a control propagates automatically to every linked provision.
  • Hailey Evidence Validation: The control record surfaces a consolidated view of all Hailey evaluations across all linked evidence and tests, giving control owners and compliance managers a single place to see the full validation picture without navigating across individual records.
  • Scope Awareness: Filter and manage controls by system or framework, supporting organisations with distinct OT and IT environments, multiple regulatory jurisdictions, and complex entity structures.
  • Knowledge Graph Foundation: Linkages across controls, assets, systems, evidence, and tests form the connected data structure that enables Hailey to reason across the full compliance object model and supports future agentic capabilities.

Benefits:

  • Compliance status assessed once on a control flows automatically to every linked framework provision, eliminating the need to re-assess the same control multiple times across different frameworks.
  • Many-to-many linking removes the architectural constraints of the legacy module without disrupting existing workflows.
  • Consolidated Hailey validation on the control record reduces time spent navigating across tasks, evidence, and tests to understand the overall compliance picture.
  • Scope awareness keeps views clean and relevant for teams with different responsibilities across complex hybrid environments.
  • Consistent UX across all registers reduces onboarding time for teams managing multiple compliance objects.
  • Customers migrate at their own pace, with no forced cutover and full parity maintained throughout.

Example use case:

A security team at a critical infrastructure operator manages compliance across ISM, Essential Eight, and SOCI simultaneously. After migrating to the new Controls Register, they discover that 40% of their controls map to provisions across more than one framework. Assessments now propagate automatically, eliminating the duplicate effort of re-assessing the same control three times. When a new SOCI obligation is mapped to an existing ISM control, compliance status flows through immediately with no additional assessment work. The control record surfaces a consolidated Hailey validation summary across all linked evidence and tests, giving the compliance manager a single view of what has been validated, what is outstanding, and what was submitted through automated integrations versus manual task workflows.

1
2
In-Platform Review & Commenting for QBAs
In progress this quarter

The review process for QBAs often occurs outside the platform, leading to fragmented communication and limited visibility. This feature enables users to complete the entire QBA review phase within 6clicks.

Users can add question-level comments to provide context or feedback, assign comments to drive accountability, and receive notifications when they are mentioned or assigned. Comments can also be marked as resolved to track progress and maintain a clear audit trail.

This creates a centralized, transparent, and efficient review experience for QBAs, reducing reliance on external tools.

Key Components:

  • Question-Level Commenting (for QBAs): Add contextual comments directly against specific questions during the QBA review phase.
  • Comment Assignment: Assign comments to users to drive ownership and accountability.
  • Mentions & Notifications: Notify users when they are mentioned or assigned within QBA comments.
  • Comment Resolution: Mark comments as resolved to track completion of discussions.
  • Audit Trail: Maintain a clear, centralized record of all review discussions and decisions within QBAs.

Benefits:

  • Centralized Review for QBAs: Eliminates the need for external tools.
  • Improved Collaboration: Enables seamless communication during the QBA review phase.
  • Clear Accountability: Assignments ensure ownership of actions.
  • Timely Responses: Notifications keep users on track.
  • Better Visibility & Tracking: Resolution and audit trails provide clarity on progress.
  • Increased Efficiency: Reduces manual effort and speeds up reviews.

Example use case:

During a Third-Party Risk QBA, a reviewer flags an incomplete response to a data protection question and assigns a comment to the vendor owner. The owner receives a notification, updates the response with clarification, and the reviewer marks the comment as resolved—keeping the entire discussion tracked within the QBA.

1
2
In-Platform Review & Commenting for RBAs
In progress this quarter

The review process for RBAs currently happens outside 6clicks, leading to fragmented communication and limited visibility. This feature enables users to complete the entire RBA review phase within the platform.

Users can add requirement-level comments to provide context or feedback, assign comments to drive accountability, and receive notifications when they are mentioned or assigned. Comments can also be marked as resolved to track progress and maintain a clear audit trail.

This creates a centralized, transparent, and efficient review experience for RBAs, reducing reliance on external tools.

Key Components:

  • Requirement-Level Commenting (for RBAs): Add contextual comments directly against specific requirements during the RBA review phase.
  • Comment Assignment: Assign comments to users to drive ownership and accountability for actions.
  • Mentions & Notifications: Notify users when they are mentioned or assigned within RBA comments.
  • Comment Resolution: Mark comments as resolved to track completion of discussions.
  • Audit Trail: Maintain a clear, centralized record of all review discussions and decisions within RBAs.

Benefits:

  • Centralized Review for RBAs: Eliminates the need for external tools by bringing all review discussions into one place.
  • Improved Collaboration: Enables seamless communication between stakeholders during the RBA review phase.
  • Clear Accountability: Assignments ensure ownership of actions and reduce ambiguity.
  • Timely Responses: Notifications and mentions help users stay on top of required actions.
  • Better Visibility & Tracking: Comment resolution and audit trails provide clear insight into progress and decisions.
  • Increased Efficiency: Reduces manual effort and speeds up the overall RBA review workflow.

Example use case:

During an ISO 27001 RBA, a reviewer flags a vague response to an access control requirement and adds a comment, assigning it to the IT owner. The IT owner receives a notification, provides clarification, and attaches supporting details. Once reviewed, the comment is marked as resolved, maintaining a clear audit trail within the RBA.

1
1
Establish a Controls Review module similar to Risk Reviews

I.e. similar to how Risk Reviews can be created, allow the ability to create Controls Reviews.

What's good about the Risk Reviews functionality is that assigned reviewers get to see the full details of the Risk (assessments, linked controls, linked treatments, etc etc) in the Risk Review task and can make edits there without having to navigate separately to the Risk Register module.

It would be great if the same functionality could be established for Controls Reviews

0
1
ISMS Objectives Register · Security Objectives & KPI Tracker

Add a dedicated module to define, measure, and report on information security objectives as required by ISO 27001:2022 Clause 6.2. Today, most ISMS teams track this in Excel, which makes management reviews, internal audits, and trend analysis painful.
The register should let users:

Create objectives grouped by domain (Governance, Awareness & Training, Incident Management, Compliance, Supplier Management, Vulnerability Management, etc.), each linked to the relevant policy, Annex A control(s), and risk(s).
Define one or more KPIs per objective, with: data source, measurement frequency (monthly / quarterly / annually), numerator, denominator, target threshold (norm %), and reporting evidence.
Auto-compute the compliance status (Compliant / Non-Compliant) from the KPI value vs. the defined threshold, per reporting period.
Capture ownership (responsible team or individual) and review cycle.
For any Non-Compliant result, trigger a non-conformity workflow: root cause, corrective/preventive action plan, due date, follow-up, and closure evidence.
Maintain historical results to show trend over time, and feed the Management Review (Clause 9.3) and Internal Audit (Clause 9.2) modules automatically.
Export an audit-ready report (Excel / PDF) with version control and approval history matching 6clicks' existing document standards.

Business value: replaces spreadsheet-based registers, produces auditor-ready evidence for Clauses 6.2, 9.1, 9.2, and 9.3 in one click, and reduces management review prep time significantly for MSPs and internal ISMS teams managing multiple ISO 27001 certifications.

0
1
Ablity to create assessment against multiple frameworks

Ability to do one assessment and be able to map the results back against different frameworks

0
1
Custom attestation emails

The ability to customise attestation email template for clarity.

0
1
Ability to add additional provisions to custom authorities

Currently an authority once published and then brought back into draft mode, cannot have additional provisions added.

There is a need within a custom authority for additional provisions to be added after it has been published.

The work around of copying the authority and using a new one does not work because it breaks all mapping links to the new copy.

0
1
Ability to add new provisions to already published Authority registers

As part of our Regulatory Compliance workstream, we are adding a number of custom compliance registers as Authorities into the Compliance module. These compliance registers comprise of regulatory requirements applicable to our organisation under a particular compliance domain.

As part of this workstream, we will receive quarterly updates to these compliance registers - i.e. changes to existing reg requirements, removal of reg requirements no longer applicable, and new reg requirements that have been added or are now applicable.

Currently, in order for us to add new reg requirements as new provisions to an existing Authority register, we would have to create a copy of that register and add the new provisions to the copy. However, this creates an issue for us as we tag these compliance provisions to existing controls in our controls database and if we create a new copy of the Authority register (and remove the old one), we would have to redo the provision-to-control tagging on the existing authority provisions that remain unchanged (which is not ideal).

As such, our request is could we make it possible to enable the ability to still be able to add new provisions to Authority Registers that have moved from Draft to Published and back to Draft again (i.e. always retain the ability to add new provisions, similar to how you can always edit provisions even after publishing).

0
1
Undeliverable notification

Alerts for undeliverable emails.

0
1
Ability to export the assessment questions and corresponding response option for each question.

Currently the export function allows for export to a spreadsheet but only the questions are exported but not the corresponding response options.

0
1
Increase character limit beyond 2000 characters.

Currently the maximum character limit is 2,000 when completed assessments are imported into 6Clicks. We frequently exceed this maximum.

0
1
Ability to limit access to published forms

Ability to set forms to be only accessible by internal users or employees; or by authenticated 6clicks users.

0
1
Enable Full-Width Inline Editing for Controls

Description:
Currently, controls can technically be edited via the side panel (right-hand "Control details" view). However, this interface significantly limits the usability of the editor due to its constrained width.

For controls containing detailed descriptions (e.g., ISO 27001 clauses, policies, procedures), the narrow editing panel makes it difficult to:

  • Read and review content efficiently
  • Structure text properly (paragraphs, lists, formatting)
  • Perform quality assurance on longer content

Feature Request:
Introduce a full-width editing mode directly from the Controls / Control Set Builder view.

This could be implemented via:

  • A "Edit Full Screen" button** in the side panel
  • Or direct inline editing within the main content area (replacing the read-only cards)
  • Optional toggle between view mode and edit mode

Key Improvement:
Allow the description field (rich text editor) to use the full available horizontal space, similar to a document editor.

Business Value:

  • Improves readability and content quality for ISMS documentation

  • Reduces formatting errors and rework

  • Enhances user productivity during policy drafting and control definition

User Pain Point (Observed):
The current right-side panel creates a “tunnel view” effect, forcing excessive scrolling and making it difficult to visualize the full structure of the control content.

Use Case:
While drafting or reviewing ISMS controls (e.g., "Context of the Organization", "Scope", "Risk Management"), users need a document-like editing experience rather than a form-based narrow panel.


Summary:
This is not only a functional improvement but a usability and quality-of-output enhancement, directly impacting how effectively organizations can build and maintain their ISMS documentation.

0
1
Entry and Exit Requirement for Issues and Incident Workflow

Can we have for Issues and Workflow the possibility to have entry and exit requirement same as Risks Workflow. Thanks

0
1
Importing Custom Fields in Control Set
Closed

Hello
I’m experiencing an issue with importing controls within a control set in 6clicks. We have custom fields configured, but when I download or view the controls import template, the custom fields are not included (they appear correctly in other modules—for example, the risks import).
Additionally, if I manually add the relevant custom field columns to the import file, 6clicks does not import/populate those fields.
Please find attached the template file I’m trying to import for your review.
Could you please advise how we can import custom fields for controls within a control set, or confirm if there are any limitations/settings required for this functionality?

2
1
Ability to edit comments

Hello,
Would it be possible to enable the ability to edit or delete comments in the Risk module (for example), while ensuring full auditability and proper tracking of changes?
Thank you.

0
1
Control Mapping Explorer

The Control Mapping Explorer enables users to navigate and visualize relationships between controls across multiple cybersecurity and compliance frameworks (e.g., ISO 27001 Annex A, CMMC, internal ISMS control sets).

From a single control reference (e.g., ISMS A.7.1), users can instantly access:

All linked control sets within the ISMS
Mapped controls from other frameworks (e.g., CMMC, NIST, etc.)
Associated policies, procedures, and evidence artifacts
Cross-references to Annex A domains and control families

The feature provides a centralized, clickable interface to:

Improve traceability between frameworks
Accelerate audits and gap analysis
Simplify control understanding for operational teams
Support multi-framework compliance strategies

This creates a single source of truth for control relationships, reducing manual mapping efforts and enhancing governance visibility.

0
1
SSO Failover URL

It would be good to have an SSO failover URL made available.

Only Administrators should be able to login via this URL using their 6clicks username, password, and MFA, and can be used to recover access if there is a problem with SSO or the iDP.

0
1
Ability to rearrange order or placement of the fields in the Third-Party Management Overview record.
0
1
Sorting of custom fields

I would like to be able to sort custom fields in any of the registers (custom or standard register). At the moment, the sorting is limited to standard fields, which is not enough.

In addition, in the Third Party module, sorting is not possible at all. Same as with all the other fields (including custom fields) in any register, sorting should be possible there.

0
1
Allow users to select and delete multiple attributes at once within the Attribute table in the “Custom Data” section.
0