Getting Started

Setting up Tidal Control

Setting up Tidal Control takes three things: activating your own account, creating and inviting the rest of your team, and deciding whether you need SSO or integrations. Data import is available if you already track compliance elsewhere.

Account activation and first login

Your invitation email carries the activation link. After activating, take a moment to get oriented in the main navigation.

Account activation

You have received an invitation email with instructions for account activation. This email contains:

  • Account activation link - Direct access to Tidal Control
  • Organisation URL - Your specific Tidal environment
  • Password setup - Via Keycloak authentication system

Activation steps:

  1. Click activation link in invitation email
  2. Set password via web interface
  3. Log in to your organisation Tidal environment
  4. Explore dashboard for initial orientation
Tip

Haven't received the email? Check spam folder or contact support@tidalcontrol.com

Interface orientation

The main menu splits into three areas: your own dashboard, day-to-day compliance work, and organisation-wide setup.

Understanding main navigation:

  • Dashboard - Personal dashboard with assigned tasks
  • Compliance section - Frameworks, Controls, Tasks, Tests
  • Organisation section - Plans, Risks, Vendors, Assets, Policies
  • Settings - Users, integrations, system configuration

User management (for Super Users)

If you are a Super User, configure team access before starting compliance work.

Adding team members

Create a user from Settings → Users with just their name and email to start.

Creating users:

  1. Go to Settings → Users

Users overview

  1. Click "Add User" in top right
  2. Fill in basic information:
    • First name and last name
    • Email address (becomes login identifier)
  3. Click "Create"

Add user dialog

Assigning roles

Set each user's role from the dropdown in their row, based on what they actually need to do.

Choose appropriate role per user:

  • Read Only User - View access only, no execution rights
  • Regular User - Standard compliance staff
  • Super User - Administrators with full access

Role assignment:

  • Click Role dropdown in user row
  • Select desired role
  • Change takes effect immediately

Role assignment

For comprehensive explanation of user roles and access rights, see Getting started with user management.

Sending invitations

A user can't log in until you send the invite from their Actions menu.

Activating users:

  1. Click "Manage" per user
  2. Select "Send invite"
  3. User receives activation email
  4. User follows same activation process

User actions menu

For detailed user management, see Creating and managing users.

Strict Mode considerations

Organisations in Strict Mode have granular access control per compliance object:

  • Regular Users only see assigned objects
  • Object-level roles required (Viewer, Contributor, Owner)
  • Explicit assignment needed for controls, assets, risks

Strict mode user overview

For complete Strict Mode configuration, see Strict Mode and granular access control.

Data import support

If you already track compliance elsewhere, Tidal Support can import it rather than you retyping it.

Existing compliance data: Tidal Support can import:

  • Existing controls and policies
  • Risk registers and risk assessments
  • Asset inventories
  • User accounts and their assignments

Import request: Email support@tidalcontrol.com with:

  • Current compliance data (spreadsheets, documents)
  • User list with roles
  • Required frameworks

Optional configuration

Two things are worth setting up early but are not required to start: single sign-on and your first integrations.

Single Sign-On (SSO)

For organisations with centralised identity management:

  • Centralised authentication via existing identity providers (Azure AD, Google, Okta)
  • Automatic user deactivation upon employee departure
  • Multi-factor authentication via organisational policies

SSO setup requires IT administrator access to your identity provider. Configuration can be done in parallel with compliance work. For complete SSO configuration instructions, see Configuring Single Sign-On (SSO).

Integration preparation

External system connections for automated compliance:

  • Cloud platforms (AWS, Azure, GCP)
  • Development tools (GitHub, GitLab)
  • Business applications (Google Workspace, Jira)

Integration planning:

  • Inventory available systems - Which tools do you use?
  • Prioritise critical systems - Which have highest compliance impact?
  • Plan configuration timing - After basic compliance setup

For complete integrations overview, see Getting started with Integrations.

Setup validation checklist

Run through this before moving on to framework implementation.

Before proceeding:

  • Account activated and password set
  • Team users created and invited
  • Roles assigned according to organisation structure

And, where relevant:

  • Strict Mode configured
  • Data import prepared and executed
  • Single Sign-On configured
  • Integrations configured

Next steps

With basic setup complete you can begin framework implementation:

  • Document organisational context
  • Perform risk analysis and select controls
  • Create asset inventory and perform business impact analysis
  • Start control implementation
  • Collaborate in teams on tasks