Skip to content

Organization Overview ​

An organization is the workspace boundary in Modulos. It defines who can access the platform, which shared libraries exist, and which defaults apply across projects.

What this is ​

Organizations let you scale governance without losing consistency:

  • teams share the same language for risk and compliance
  • leadership sees portfolio-level signals across projects
  • changes are governed centrally while execution happens in projects

Where in Modulos ​

Most organization configuration is managed by organization admins, but viewable by regular members.

  • Organization → Users to view members, invites, and roles
  • Organization → Settings to view organization-wide defaults like currency and language

Organization-scoped configuration that impacts projects is documented in its feature areas:

Who can do what ​

Permissions

  • Organization Admins manage organization settings and user access.
  • Organization Members can typically view organization settings and membership, but cannot change them.
  • Organization Risk Managers maintain risk quantification structure across the organization, such as taxonomy and budgets, and support teams running quantification in projects.
  • Organization Policy Managers review, approve, and publish policy versions in Policy Center.

Organization roles do not automatically grant project access. Project work is governed through project roles.

How it works ​

Organizations provide shared structure that projects build on:

  • People: membership and organization roles
  • Defaults: currency and language preferences used across the UI and exports
  • Shared libraries: organization-level risk taxonomy and budgets used for risk quantification rollups
  • Projects: where frameworks, Controls, Evidence, and quantification runs are executed

Projects inherit organization defaults and rely on shared libraries for consistency, while still allowing project-specific scope and ownership.

How to use it ​

Important considerations ​

  • Organization defaults matter most early; changing currency later does not retro-convert historical values.
  • Separation of duties improves audit readiness: where possible, the people who implement Controls should not be the ones who review and fulfill the Requirements those Controls support.
  • If you can’t access an organization page, you likely don’t have the required organization role.