Getting Started
Advanced setup and customisation
This article is for setups that go beyond the standard templates: writing your own controls and risks, mapping them to each other and to frameworks, and creating one-off tasks that no plan generates. If the templates cover you, you do not need any of it.
When to use advanced setup
This article is for users who need to customise their Tidal Control environment beyond the basic templates. Use these instructions when:
- Starting without a template and need to build your compliance framework from scratch
- Modifying existing templates to fit specific organisational requirements
- Adding custom controls not covered in standard frameworks
- Creating manual tasks for one-off compliance activities
Creating and managing controls
Custom controls cover the requirements your frameworks do not, and they behave like any other control once linked.
Adding new controls
Create controls that aren't included in standard frameworks:
- Go to Compliance → Controls
- Click "Add control" in top right

- Fill in control details:
- Name - Clear, descriptive name
- Description - What the control achieves + specific test steps for your organisation
Linking controls to frameworks
Mapping a custom control to a framework requirement is what makes it count towards that framework's progress.
Connect custom controls to compliance frameworks:
- Go to Frameworks section
- Select target framework (ISO 27001, SOC 2, etc.)
- Click "Link control" for relevant framework section

- Map control to framework requirements - Select applicable clauses or requirements
For detailed framework management, see Frameworks getting started.
Control implementation tasks
Use Plans to automatically create tasks for new controls.
You can also add manual tasks:
- Open control details page
- Click "Add task" in tasks section

- Configure task parameters:
- Task type - Implementation, review, or testing
- Assignee - Team member responsible
- Due date - Implementation deadline
- Priority - High, medium, or low
For comprehensive task management, see Creating and managing tasks.
Risk management and control mapping
Custom risks work the same way, and linking them to controls is what records how each risk is being treated.
Creating custom risks
A custom risk is created the same way as any other, from the Risks page.
Add risks specific to your organisation:
- Go to Organisation → Risks
- Click "Add risk" in top right

- Define risk parameters:
- Name - Choose a clear, descriptive name for the risk
- Custom ID - Your own reference number (e.g., "R.IT.01", "R.HR.03")
- Assign owner - Select the responsible person from the dropdown
- Description - Explain what this risk entails and why it's relevant
Linking controls to risks
Link a risk to the controls that mitigate it from the control's own Risks tab.
Connect risks to mitigation controls:
- Open control details page
- Click on "Risks"
- Search or select relevant risks
For comprehensive risk management, see Creating and editing risks.
Creating tasks and automating with plans
Beyond standard control implementation, you often need specific one-off tasks. Think of audits, external assessments, or organisational changes that don't fit into regular compliance cycles. Tidal offers flexible options for both manual task creation and automated batch creation via plans.
Creating a task
- Go to the Tasks page via the main menu
- Click "Add task" in the top right of the overview
- The creation form opens where you can fill in task information

Filling in task information
Only the name and type are required; everything else can be filled in later.
Required fields:
- Name - Choose a clear, descriptive name for the work
- For example: "Conduct management review" or "Test backup procedure"
- Task Type - Select Execution or Assessment
Optional but recommended fields:
- Assign owner - Assign responsible person
- Description - Extended context and instructions
Automatically creating tasks
-
Go to Organisation → Plans
-
Click "Add plan" to create new plan

-
Configure plan settings:
- Plan name - Descriptive identifier
- Scope - Select specific assets or controls
- Execution schedule - Set to next hour for immediate execution
-
Set execution date:
- Creation date - Set to next hour or another future date
- Due date - Leave empty or set to a date after the creation date
Tidal automatically creates tasks when the execution time arrives. Monitor progress in the Tasks section.
You can also use the Plans functionality to create a one-off Plan that creates tasks in one go for a selection of controls and/or assets.
In this case, set the Creation date to next hour, and set the 'Valid to' date of the Plan to tomorrow. The Plan will then run once and deactivate itself afterwards.
For comprehensive plan management, see Creating and configuring plans.
Asset and policy integration
Your custom controls and risks still need to be attached to the assets and policies they apply to.
Connecting custom elements
Link your custom controls and risks to existing assets:
- Go to control or risk details
- Navigate to "Assets" tab
- Select relevant organisational assets - Systems, processes, or data that the control protects
For policy connections:
- Controls link to policies via tests and evidence requirements
- Use policy management to create supporting documentation
For detailed policy management, see Creating and editing policies.
Testing and validation
Before relying on a custom setup, confirm each part of it does what you expect.
Ensure your custom setup works effectively:
- Test control implementations - Verify controls achieve intended outcomes
- Validate risk assessments - Confirm risk levels reflect actual organisational exposure
- Monitor task completion - Track progress on manual and generated tasks
- Review framework compliance - Check that custom controls meet framework requirements
For comprehensive testing approaches, see Executing and monitoring tests.
- Next
- How Tidal works